Bast handles SSH configuration and private-key files, so security reports should not be filed as public issues when they contain sensitive details.
Please use the repository's GitHub private vulnerability reporting feature. Include the affected version, impact, reproduction steps using disposable keys and hosts, and any suggested mitigation.
Do not send real private keys, passphrases, hostnames, IP addresses, or complete SSH configuration files. Bast will never ask for them in a bug report.
Security fixes are supported for the latest released version.