Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Report them through GitHub's private vulnerability reporting instead: go to this repository's Security tab and choose Report a vulnerability. That opens a private advisory visible only to the maintainers.
Please include:
- the version of this SDK, and the Go version you are building with
- what an attacker could do with the issue
- the smallest set of steps that reproduces it
- any proof-of-concept code, if you have it
This repository is the Go client library for the Firezone REST API. If you believe you've found a vulnerability in the Firezone product itself (e.g. the portal, the Gateway, or a Client) please file the bug in the firezone/firezone repository rather than here.