If you discover a security vulnerability, please report it privately to the maintainers:
- Email: security@basicmails.example (replace with real contact)
- Or open a confidential issue and add the label
security(do not include exploits or secrets in public issues).
We will acknowledge receipt within 48 hours and aim to provide a remediation timeline.
We will provide security fixes for the latest stable release and the previous minor release. If you are running an older version, consider upgrading.
Please do not publicly disclose vulnerabilities until a fix or mitigation is available. We appreciate coordinated disclosure.
- Keep private keys and secrets in a secure vault.
- Use TLS for SMTP and API endpoints.
- Rotate API keys on compromise.