Security fixes target the latest commit on main.
Use GitHub’s private vulnerability reporting feature for this repository. Do not open a public issue with exploit details, private data, access tokens, or credentials.
Include the affected route, the impact, clear reproduction steps, and any proposed remediation. We will confirm receipt, investigate the report, and coordinate disclosure after a fix is available.
The public tools never need secrets in browser code. Treat any exposed credential as compromised and rotate it before submitting a patch.