Security policy

Reporting a vulnerability

Please report security issues privately to Bartosz Supcziński at bartek@env.pl. Do not open a public issue before the maintainer has had a reasonable opportunity to investigate and prepare a fix.

Include the affected version, a concise reproduction procedure, the expected impact, and any suggested mitigation. Never include real Wi-Fi, OTA, Home Assistant, or web-interface credentials in a report.

Security model and limitations

Only the latest tagged release is intended to receive security fixes.