Do not open a public issue for a suspected vulnerability. Use the repository's private vulnerability-reporting feature. Include the affected commit, threat, reproduction, and whether any real credential or personal data may be involved.
Only the current main branch is supported. Maintainers will acknowledge a
report, assess severity and affected releases, prepare tests and a fix in a
private fork, and publish an advisory with the corrected release.
Never send production attestation tokens, nullifier secrets, account keys, email-challenge proofs, identity exports, or cloud credentials in a report.