We take security seriously and appreciate responsible disclosure.
The latest released version and the main branch receive security fixes.
- Do not open public issues for security reports.
- Please use GitHub Security Advisories (preferred) or contact the maintainers privately.
- If private contact info is not yet listed, open a minimal issue asking for a security contact method.
Provide as much detail as possible, including reproduction steps and affected versions. We will acknowledge receipt within 72 hours and provide a timeline for remediation where possible.
- Never include real
apptokenor user identifiers in issues, PRs, or logs. - Redact tokens in any diagnostic output.
- Please flag any high or critical findings.