Security fixes are applied to the latest released version.
Please report vulnerabilities through GitHub Security Advisories:
- Open the repository Security tab.
- Click "Report a vulnerability".
- Include reproduction details, impact, and any suggested fix.
If private reporting is unavailable, open a private channel with the maintainer and avoid posting exploit details publicly.
- Never commit API keys, tokens, session files, or
.envfiles. - Use repository secrets for CI publishing credentials.
- Rotate credentials immediately if exposed in terminal output, logs, screenshots, or chat.