Security fixes target the latest released DurinDoor version. Reproduce a report on the latest release before submitting when possible.
Use GitHub Security Advisories. Do not open a public issue, discussion, or pull request containing exploit details or credentials.
Include the affected version, deployment method, impact, reproduction steps, and a minimal proof of concept with secrets removed.
Maintainers will confirm receipt through the private advisory, investigate, coordinate a fix and release, and agree on public disclosure after affected users can update. Response and release time depend on severity and reproducibility.