MailMate is an actively developed prototype. Security fixes are applied to the
current main branch; older branches and snapshots are not supported releases.
Please do not disclose suspected vulnerabilities in a public issue.
Use GitHub's private vulnerability reporting flow:
https://github.com/MailMateCS/MailMate/security/advisories/new
Include the affected component, reproduction steps, expected impact, and any suggested mitigation. Do not include real mailbox content, credentials, OAuth tokens, API keys, or other personal data in the report.
Maintainers will acknowledge a complete report when it is reviewed and will coordinate remediation and disclosure according to the severity and scope of the issue.