Do not open a public issue. Submit the report through GitHub private vulnerability reporting.
Include a description, reproduction steps or proof of concept, potential impact, and any suggested remediation. Remove customer data and credentials.
The maintainer will acknowledge a complete report on a best-effort basis. Coordinated disclosure timing will be agreed through the private advisory.
Only the latest commit on main is supported.
This policy covers code in this repository. Databricks platform vulnerabilities must be reported through Databricks Security.
See Security Architecture for Forge's data flows, authentication model, and mitigations.