Please do not open a public issue for a suspected vulnerability. Use GitHub's
private vulnerability reporting for vestavision/trail.
Include the affected version or commit, reproduction steps, impact, and any known mitigations. We will acknowledge a complete report as soon as practical and will coordinate disclosure after a fix is available.
Until Trail publishes its first stable release, security fixes are made on the
latest main branch. After stable releases begin, this file will list the supported
release lines explicitly.
Never include real credentials, tokens, provider payloads, or customer data in a report.