Security fixes are applied to the latest commit on main. This project has not published a stable release series yet.
Use GitHub private vulnerability reporting. Do not open a public issue or attach raw logs, prompts, paths, credentials, account identifiers, or customer data.
Include a synthetic reproduction, affected files, impact, and proposed mitigation. You can expect an acknowledgement within five business days. Disclosure timing will be coordinated after validation and remediation.
Claude Code JSONL logs can contain source code, credentials, file paths, prompts, command output, and personal data. Run the pipeline on storage you control, restrict database access, and review every export before sharing it. This repository does not need or accept private corpora.