fenvoy has not undergone any independent security audit. No third-party review has been performed. Use at your own risk. Refer to the README for the full disclaimer.
Found a security issue? Feel free to reach out through any of the following channels:
- GitHub Issue / Pull Request: Opening a public issue or submitting a fix directly is completely acceptable. It gets things moving faster and keeps the community in the loop.
- GitHub Private Advisory: If you'd rather handle things quietly before anything goes public, a confidential advisory works just as well.
- Email: Prefer a direct line? Reach the maintainers at fenvoy@mailfence.com
When reaching out, the more context you can provide, the better:
- What the vulnerability is and how it works
- How to reproduce it
- What the potential impact might be
- A proposed fix, if you have one in mind
We handle security issues through a coordinated disclosure process. A public advisory will be released once a fix is in place. We appreciate being given a reasonable window to address the issue before any public disclosure.