Security fixes are provided for the latest stable Phalcon Kit App release. Applications created from older skeleton releases should update their direct dependencies and manually adopt relevant skeleton hardening changes.
Do not open a public issue for a suspected vulnerability. Use GitHub's private
security advisory reporting for
phalcon-kit/app.
Include the affected version, reproduction details, expected impact, and any known mitigations. Never include production credentials, customer data, or private infrastructure details.