Please report suspected security vulnerabilities privately to fickleheartedkeys@163.com before posting technical details in a public issue.
Include the affected Pebrel version, operating system, reproduction steps, expected and observed behavior, and the potential impact. A small reproduction using test data is preferable to logs containing real credentials or private conversations.
Do not send passwords, access tokens, private keys, or unrelated personal data. Use public issues for ordinary bugs that do not expose a security vulnerability.
Use the latest stable release when checking whether a problem is still present.
Mention if it also affects a Preview build or the current main branch.
Older releases remain available for reference; availability does not imply
that every older version receives fixes.
The maintainers will review the report and coordinate any necessary fix and public disclosure. This policy does not promise a response deadline or a bug bounty.