Skip to content

Security: TPB003/TP_QRCODE

Security

SECURITY.md

Security policy

Please do not disclose vulnerabilities, credentials, private QR payloads, or customer data in public issues. Contact the repository maintainers privately through the GitHub security-advisory flow and include a minimal reproduction, affected route/package, impact, and a suggested mitigation. Allow reasonable time for a fix before public disclosure.

The local development code and fixed verification code are for tests only. Production deployments must configure real email delivery, Turnstile, HTTPS, secrets, rate limits, logging, and backups.

There aren't any published security advisories