Security policy
Public security discussion
Public issues and comments are welcome for general security concerns, defence-in-depth suggestions, threat-model discussions, and vulnerabilities that have already been disclosed.
If a report describes a previously undisclosed vulnerability that could enable exploitation, contributors are encouraged to report the sensitive details privately through GitHub Security Advisories for epicecu/table, or by email to David Cedar at david@epicecu.com. A public issue may still identify the general concern, provided it does not include exploit instructions, credentials, keys, private device payloads, or real vehicle information.
Private reports should include affected versions, a minimal reproduction, and any known impact. Security fixes and relevant technical details may be discussed publicly after the issue has been assessed and sensitive risks have been addressed.
