Do not open a public issue for a vulnerability that could expose secrets, bypass approval checks, escape the restricted SSH account, or affect resources outside the configured boundary.
Report the issue privately through GitHub's security advisory feature. Include the affected boundary, expected and observed behavior, a minimal reproduction using generic fixtures, and the relevant OpsHaven version or commit.
Do not include real credentials, hostnames, IP addresses, customer information, private infrastructure details, or unrelated project identifiers.
Security fixes are applied to the latest released version and the current main branch.