Report vulnerabilities through the repository security advisory flow when available. Do not open public issues for exploitable vulnerabilities or leaked secrets.
Before publishing any release, run a secret scan and dependency review. Credentials from the legacy project must be rotated and must not be reused.