Security fixes are provided for the latest released version.
Do not open a public issue containing credentials, private source-bundle data, or local configuration. Use GitHub's private vulnerability reporting feature for this repository. Include a minimal reproduction with synthetic data.
Remove source-bundle contents, home-directory paths, MCP environment values, state files, backups, and command output that identifies a machine or account. The JSON plan format intentionally excludes configuration values and is the preferred diagnostic starting point.