Security fixes are applied to:
main- the latest tagged release
Please do not open public issues or pull requests for potential vulnerabilities.
Instead, report privately to:
febysyarief.dev@gmail.com
This inbox is monitored by Feby, the current project maintainer.
Response targets:
- Initial acknowledgement within 3 business days
- A follow-up triage update within 7 calendar days
Use a subject line such as [oceandl security] <short summary> when possible.
Include:
- Affected version/commit
- Reproduction steps or proof of concept
- Expected vs. actual behavior
- Potential impact
If you are unsure whether an issue is security-sensitive, report it privately first.
If a report is opened publicly by mistake, maintainers may limit public discussion, remove sensitive details, and continue the conversation privately.
We coordinate disclosure after a fix or mitigation is ready.