This repository contains our security policy and vulnerability disclosure process.
For instructions on how to report a vulnerability, read SECURITY.md.
We thank the researchers who report vulnerabilities to us. Valid, original findings earn a place here, credited by name, by handle, or kept anonymous, whichever you prefer. Say which you want when you send your report.
| Date | Researcher | Report |
|---|---|---|
| September 3, 2026 | Anjali Humnabade | Sessions signed in before you turn on two-factor authentication stayed valid afterward |
