Security fixes are applied on the main branch.
Please report suspected vulnerabilities privately through GitHub Security Advisories for this repository.
If private reporting is unavailable, open an issue with minimal details (no exploit code, tokens, or sensitive logs) and note that maintainers should move follow-up to a private channel.
- Do not publish proof-of-concept exploit details before a fix is available.
- Rotate any exposed credentials immediately.
- Include reproduction steps, impacted paths, and mitigation ideas when possible.