Please do not open a public GitHub issue for security reports.
Email hi@passionseed.org and cc me@tinywifi.cc (Product Security Engineer). Include:
- A description of the issue and its potential impact
- Steps to reproduce, or a proof of concept
- Affected URLs, routes, or components if known
We aim to acknowledge within 48 hours and will keep you updated as we investigate and fix.
The live application at www.passionseed.org and everything in this repository, including the hackathon subsystem and API routes under app/api/.
- No destructive testing, credential guessing, or load testing against the production site.
- Don't access or modify other users' data. If a proof of concept requires data access, use accounts and data you created yourself.
- We appreciate good-faith research and will credit reporters if they'd like (with permission).