Please report security issues privately to the maintainer listed in the repository profile.
Do not open public issues for:
- leaked tokens or credentials
- notification webhook URLs
- private workspace exports
- bounty target details that are not already public
Open Bounty Radar is local-first. Keep secrets in environment variables and keep generated reports out of commits unless they are scrubbed demo artifacts.