Security fixes are applied to the latest version on the default branch.
Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting for this repository:
https://github.com/TechBeme/open-higgsfield/security/advisories/new
Include the affected route or component, reproduction steps, potential impact and any suggested mitigation. Do not include live provider credentials or personal media.
Open-Higgsfield connects to paid third-party APIs. Operators are responsible for authentication, rate limiting, spend controls, data retention and compliance requirements in their own deployments.