Report suspected vulnerabilities through the main project's private advisory form. Do not open a public issue for an undisclosed vulnerability.
Include the affected version or commit, reproduction steps and the impact. Do not include private keys, recovery phrases or confidential transaction data.
For the project's support scope and disclosure process, see the ClearSign security policy.
Ordinary website bugs can be reported in this repository's issues.