Please do not open a public GitHub issue for security vulnerabilities.
If you discover a security issue, report it privately using one of these methods:
- GitHub private vulnerability reporting — use the Report a vulnerability button on the Security tab of this repository
- Email — send details to 142175+joshholl@users.noreply.github.com
Include as much detail as you can: what the issue is, how to reproduce it, and any potential impact. You'll receive a response as soon as possible.
Frollz is a self-hosted application. The security boundary is your own infrastructure — the application is not offered as a hosted service. Reports related to insecure default configuration, dependency vulnerabilities, or injection flaws in the application code are all in scope.