Public Issues and Discussions are not the place to report security vulnerabilities or to share sensitive details. Anything posted here is public and indexed.
If you believe you have found a security issue in a MarrowGlass system, report it privately using GitHub's private vulnerability reporting:
Report a security vulnerability →
When reporting, include enough detail to reproduce the problem without exposing real systems or real users.
Never publish, in an Issue, Discussion, or advisory draft, any of the following:
- credentials, passwords, API keys, tokens, or connection strings
- exploit details that could be used against a live client system before a fix is available
- private source code you do not have the right to share
- database contents or records tied to real people
- customer data, even when redacted carelessly
If a demonstration is needed to make a report clear:
- Use a throwaway environment you control, not a production system.
- Sanitize every example. Replace real names, emails, tokens, and identifiers with clearly fake values.
- Provide reproduction steps that work against the demonstration, not against a live system.
- Prefer screenshots with redaction over raw dumps.
This policy covers the intake process and the systems MarrowGlass operates for clients. Reports about third-party dependencies should be filed with the upstream maintainer; we will coordinate where we are responsible.
We acknowledge private reports, prioritize based on impact and exploitability, and coordinate disclosure with you. We do not publish a public security email address on this page — private vulnerability reporting on GitHub is the intended channel.