Security fixes target the latest release on main.
Please do not open a public issue for an exploitable vulnerability. Use GitHub private vulnerability reporting when enabled, or contact the repository owner through the email listed on the GitHub profile.
Include the affected version, reproduction steps, impact, and a minimal fix suggestion if available. Never attach credentials, personal data, or proprietary robot logs.
The overlay makes no network requests by default. A contribution that adds export, sockets, analytics, or remote telemetry must be opt-in, document the destination and retention, and include a threat model.