Where this file is silent, the laranail security policy applies.
| Version | Status |
|---|---|
| 0.x | Active support |
Please do not open a public GitHub issue for security-sensitive findings. Email security@simtabi.com with a description, reproduction steps, and the affected version(s). We aim to acknowledge within 72 hours.
Prefer GitHub private vulnerability reporting when you can: open it from this repository's Security tab. The report arrives attached to the repo with a draft advisory and a CVE request path already in place. Email is the fallback for anyone who would rather not use GitHub.
- Wizard routes are protected by the install-once guard, CSRF (the
webgroup) and rate limiting. - The web layer never writes the
.envor the database directly — all work is delegated to the headless engine, which writes the.envatomically and masks secrets in logs.