Report a vulnerability
Send a private report through the DevCodes contact channel with affected product/version, reproduction steps and impact. Do not publish exploit details before a fix window is agreed.
Security reports should have a clear path, predictable acknowledgement, and responsible handling.
Send a private report through the DevCodes contact channel with affected product/version, reproduction steps and impact. Do not publish exploit details before a fix window is agreed.
Security fixes target currently supported releases. Keep products updated before requesting compatibility help for older versions.
Confirmed issues are triaged, patched, regression tested and documented in release notes with appropriate disclosure timing.
License validation may protect hosted services and updates, but it must never delete customer files, content or databases.