We take the security of fit-go seriously. If you discover a security vulnerability, please report it responsibly.
Please do not open a public GitHub issue for security vulnerabilities.
Instead, report it privately by either:
- Using GitHub's private vulnerability reporting on this repository (Security tab → "Report a vulnerability"), or
- Emailing the maintainers at security@gofynd.com.
Please include:
- A description of the vulnerability and its impact.
- Steps to reproduce or a proof of concept.
- Any suggested remediation, if known.
We will acknowledge your report as soon as possible, investigate, and keep you informed of the resolution. Once a fix is available, we will coordinate disclosure with you.
Security fixes are applied to the latest released version on the main branch.