Please do not open a public issue for a suspected vulnerability that could expose users, credentials, infrastructure or private data.
Until a dedicated disclosure channel is published, contact Brida maintainers privately through the security contact listed on the Brida organization/profile.
- never submit real API keys or provider credentials;
- use synthetic fixtures only;
- do not publish exploit details before coordinated remediation;
- fork PR workflows must not receive production or publishing secrets;
- generated artifacts must not contain local/private paths or source maps with internal data.
Brida may temporarily restrict discussion or publication while a vulnerability is investigated.
Security reports do not grant permission to access data or systems beyond what you are authorized to test.