Security fixes are applied to the latest commit on main. This project has not published a stable release series yet.
Use GitHub private vulnerability reporting. Do not open a public issue or include credentials, private transcripts, or customer data in a report.
Include the affected file or pattern, reproduction steps, impact, and any proposed mitigation. You can expect an acknowledgement within five business days. Disclosure timing will be coordinated after the report is validated and a fix is available.
The repository contains reference implementations. Operators remain responsible for reviewing copied code, constraining shell commands, protecting evidence artifacts, pinning dependencies, and testing integrations against the versions they deploy.