Security reporting
Report vulnerabilities privately with a safe, reproducible test case and no real secrets or user data.
Lumen is pre-release. Only the current main branch receives security fixes until tagged support
windows are published. Architecture documents, scanners, and automated tests are defense in depth;
none alone proves that a vulnerability is absent.
Report privately
Use GitHub private vulnerability reporting for the Lumen repository. Do not open a public issue for a suspected vulnerability and do not publish exploit details before maintainers coordinate disclosure. If private reporting is unavailable, contact the repository owner privately through the maintainer's GitHub profile without sending secret material in the first message.
Include the affected commit, affected boundary, expected and observed behavior, security impact, a minimal reproduction using synthetic data, and any known mitigation. Sanitize logs and screenshots. Never attach real credentials, private research, proprietary datasets, personal information, or a production database export.
Test safely
Test only systems, accounts, projects, and data you own or have explicit authorization to assess. Keep traffic and resource use bounded. Do not persist access, move laterally, exfiltrate data, degrade service, contact other users, or use a finding to access unrelated provider resources. Stop once you have enough evidence for a reproducible report.
What to expect
Maintainers will acknowledge the report, validate its scope, coordinate a fix and disclosure, and credit the reporter when requested and safe. Response and remediation times are best-effort until a published support policy replaces this pre-release policy. A report may require follow-up evidence at the actual boundary before severity or completion can be established.
If you suspect a credential or private datum was exposed, revoke or rotate it through its owner and preserve access-controlled evidence. Do not place incident details in the public execution ledger or a pull request. For product defects without security impact, use support.