Public security updates
Dopbase records security work in monthly public summaries. Each entry describes the improvements and verification completed during that development period.
These pages do not reproduce internal reports or raw scanner output. They leave out credentials, tokens, customer data, private endpoints, local paths, test payloads, and details that could help someone attack a live system.
Monthly reports
The series uses YYYY-MM filenames. A new entry is added when a month includes development or security work. The summary is written against the public revision being documented, so unfinished changes are not presented as shipped.
To report a vulnerability, follow the private process in the security model.