Security fixes are applied to the current main branch. This early project does
not yet maintain multiple release lines.
Please use GitHub's private vulnerability reporting feature for this repository. If it is unavailable, contact the repository owner through the private contact method on their GitHub profile.
Do not include real OAuth tokens, API keys, view codes, ingest tokens, raw CLI logs, personal usage data, or a live vulnerable deployment in a public issue.
Useful reports include:
- the affected commit;
- the trust boundary that can be crossed;
- a minimal reproduction using synthetic values;
- the expected impact;
- a suggested mitigation, if known.
General provider endpoint breakage without a security impact can be filed as a normal compatibility issue.