Report a Vulnerability

Report it privately: use Report a vulnerability on the repository's Security tab, or mail dev@local.link. Please don't open a public issue or pull request for it.

Say what is affected (lnk, a plugin, the relay, install.sh, the website, or the hosted service at local.link) and how to reproduce it. You'll get an answer within a few days. Fixes are credited in the release notes unless you'd rather not.

Only the latest release of lnk (lnk upgrade) and the relay running at local.link get fixes. Relays update themselves within minutes of a release. A report of a gap already listed on these pages is still welcome if you see a way to make it worse than described.