Report vulnerabilities privately to the maintainers (GitHub → Security → Report a vulnerability, or the contact in CODEOWNERS). Do not open public issues for security problems.
We aim to acknowledge within 2 working days and to fix critical issues within 7 days. Supported: the main branch and the latest release.
Never commit credentials. If one is exposed: rotate it first, remove it second, purge history third.