Please do not open a public issue for a suspected security vulnerability.
Use GitHub's private vulnerability reporting or security-advisory feature for this repository. Include the affected version, reproduction steps, impact, and any suggested remediation.
Security reports involving path validation (the safe-root guard), deletion behavior, glob expansion, or run-statistics handling are especially important. Reports will be acknowledged as soon as practical; timelines depend on severity and reproducibility.
Only the latest stable release and the latest revision on the default branch receive security fixes.