Security fixes are expected to target the latest released version.
Do not open a public issue for suspected security vulnerabilities.
Report vulnerabilities through the repository security advisory channel. If that channel is not available yet, contact the project maintainers privately through the repository owner.
Include:
- affected package version or commit;
- reproduction steps;
- expected and actual impact;
- whether credentials, tokens, mailboxes, browser profiles, or generated test artifacts are involved.
This package is a generic test harness. Project-specific credentials, customer data, mailbox configuration, browser profiles, auth state, screenshots, traces, and run artifacts must stay in consuming projects and must not be committed to this repository.