Please report vulnerabilities privately to the repository maintainer before opening a public issue. Until a public security contact is configured, do not include real session content, credentials, absolute personal paths, or archive files in reports.
The current supported line is 0.3.x. It remains a preview and should be exercised against
synthetic data before live use.
Useful reports include the command, exact error code, platform, Node version, Codex version, filesystem type, and a minimal synthetic reproduction. Redact session IDs and local paths when they are not necessary.