Security fixes target the latest stable Caelestis release and the current main branch.
Do not open a public issue. Use GitHub private vulnerability reporting so maintainers can investigate before details become public. If the private form is unavailable, email security@mia.cx.
Include the affected component and version, the impact, reproduction steps, and any known workaround. Remove credentials and personal data from screenshots and logs.