Please do not disclose security vulnerabilities in a public issue. Report them privately through GitHub's security advisory form.
Include the affected version, reproduction steps, and the potential impact. We will acknowledge reports as soon as practical and coordinate a fix or mitigation before public disclosure.
TrueMeter makes no runtime network requests. Reports involving display-label permissions, local calibration storage, package supply-chain behavior, or unexpected data access are especially valuable.