Security fixes are applied to the latest published version. Upgrade to the latest release before reporting an issue that may already be resolved.
Report vulnerabilities through GitHub private vulnerability reporting. Do not open a public issue for an undisclosed vulnerability.
Include the affected version, configuration shape with secrets removed, reproduction steps, impact, and any proposed mitigation. Never include API keys, authorization headers, unredacted cache files, or private provider responses.
You should receive an initial response within seven days. Details will remain private until a fix and coordinated disclosure are ready.