We value and encourage responsible reporting of security issues.
If you discover a vulnerability in any Marmot project or have security concerns, please contact us at security@marmotdata.io. You can also use GitHub's private vulnerability reporting, which opens a draft advisory that only we can see.
If possible, include:
- Steps to reproduce
- Affected version or commit
- Impact summary
We run a bug bounty and a Vulnerability Research Program. For scope, rules of engagement, rewards and safe harbor, see: https://marmotdata.io/bounty
Thank you for helping keep the project safe.