Do not report vulnerabilities in public issues. Use your repository's private security-advisory channel.
When reporting, include affected versions, impact, reproduction steps, and a minimal proof of concept. Avoid including real biometric samples, access credentials, camera footage, or secrets.
Laravel Bulwark is security-sensitive software. Deploy behind TLS, use high-entropy device secrets, isolate IoT networks, rotate credentials, and keep local fail-safe behavior outside the web application.