Security fixes are applied to the latest development line on main and the most recent alpha tag.
- Do not open public issues for security vulnerabilities
- Report privately through GitHub Security Advisories when available
- If that is unavailable, contact the maintainer directly before disclosure
Include:
- affected workflow or app area
- reproduction steps
- expected and actual impact
- whether user data, credentials, or device control are involved