This policy applies to actively maintained BitcoinerLab repositories.
Repositories marked as archived or deprecated, including historical projects and contribution forks, are outside the scope of BitcoinerLab's currently supported and security-reviewed codebase.
Security reports are welcome for actively maintained BitcoinerLab projects.
If you believe you have found a security vulnerability, please do not open a public issue, pull request or discussion containing details of the vulnerability.
The preferred method is to use GitHub Private Vulnerability Reporting for the affected repository:
Security → Advisories → Report a vulnerability
Alternatively, you can contact me directly:
- Email:
landabaso AT gmail DOT com - Telegram: @landabaso
- X/Twitter DM: @landabaso
For sensitive technical details or proof-of-concept exploits, GitHub Private Vulnerability Reporting is preferred.
Please include, when possible:
- the affected repository, package and version or commit;
- a description of the vulnerability and its potential impact;
- steps to reproduce it or a proof of concept;
- any conditions required for exploitation.
Please allow reasonable time to investigate and address the issue before publicly disclosing it.
Security fixes generally target the latest released version and the current main branch unless stated otherwise.