Do not report vulnerabilities or credentials in public issues.
Send security reports privately through DepthFeed contact. Include the affected package or endpoint, reproduction steps, expected impact, and a safe contact method.
Never include API keys, bearer tokens, customer information, or private data in a report or test fixture.