Please report vulnerabilities privately — do not open a public issue:
- Preferred: GitHub private vulnerability reporting (Security → Report a vulnerability)
- Email: hello@plainspace.org
You'll get an acknowledgment within a few days. Please include steps to reproduce and, if you have one, an assessment of impact.
Plainspace ships from main; the only supported version is the latest
main / the latest published container image
(ghcr.io/super-productivity/plainspace-app). Fixes are not backported.
- The hosted instance at plainspace.org runs this code; findings against it are welcome through the same channels. Please no automated scanning at disruptive volume and no testing against data you don't own.
- Self-hosted instances are operated by third parties — report infrastructure issues of those deployments to their operators.