If you discover a security vulnerability in Hushletter, please report it responsibly:
- Do NOT open a public issue
- Use GitHub's private vulnerability reporting
We will acknowledge receipt within 48 hours and provide a timeline for a fix.
| Version | Supported |
|---|---|
| Latest | Yes |
The following areas are in scope for security reports:
- Web application (
apps/web) - Email processing worker (
apps/email-worker) - Convex backend functions (
packages/backend) - Authentication and authorization flows
- Newsletter content handling and sanitization
- Public sharing endpoints