Please do not open public issues for suspected vulnerabilities. Email the repository owner with:
- a concise description of the issue,
- affected CPA Usage version or commit,
- reproduction steps,
- impact and any known workaround,
- logs or screenshots with secrets and private data removed.
Do not include CPA management keys, raw tokens, private customer data, or unredacted request payloads in reports.
Security reports for CPA Usage application code, authentication/session handling, local persistence, backup behavior, and deployment configuration are welcome.
This project does not promise a formal service-level response time, paid bounty, hosted incident response, or support for external services outside CPA Usage. Reports are handled on a best-effort maintainer basis.