Pre-release software.
helpwave/tasksis under active development and is not yet released for productive use. It has not completed a full security review, and no deployment should be treated as production-ready yet. This is expected to change over the coming month.
Please report security issues privately — do not open a public GitHub issue or pull request for a suspected vulnerability.
Follow helpwave's central vulnerability disclosure policy: https://helpwave.de/.well-known/security.txt
- Contact:security@helpwave.de
- Encryption (PGP):https://keys.openpgp.org/vks/v1/by-fingerprint/720952685A7162BDA45F27DBC62B9749E1C6B631
- Preferred languages: English, German
When reporting, please include:
- affected component and version/commit,
- a description of the issue and its impact,
- reproduction steps or a proof of concept,
- any suggested remediation.
- We acknowledge your report by email.
- We triage and confirm the issue, and agree a coordinated disclosure timeline with you.
- We develop and validate a fix on a private branch, then merge and release it.
- We credit reporters who wish to be acknowledged once a fix is available.
A machine-readable copy of these contact details is served from
.well-known/security.txt.