Security
ReqCover is a test-time build tool - it runs as part of your test suite and never ships inside the artifact you deploy. Given that, coordinated private disclosure isn’t currently a formal requirement, but it’s still welcome for anything that looks exploitable (for example, a requirements source that could be made to execute arbitrary code while parsing a malicious spec file).
Found a security issue? File it via the issue tracker, or reach out privately through one of the project’s sponsors - eSol GmbH or Nelkinda Software Craft - if you’d rather not disclose it publicly first.