Security fixes are provided for the latest stable release and, when one is available, the latest published prerelease.
Use GitHub private vulnerability reporting for this repository. Do not open a public issue containing an exploit, credential, private repository path, or captured task evidence. Include the affected version, platform, Reasonix version, minimal reproduction, and expected security boundary.
Do not test a report against repositories, providers, or accounts you do not own or have explicit permission to use. Maintainers will acknowledge a complete report, coordinate a fix and disclosure, and credit reporters who request it.
If a report accidentally includes a real credential, revoke it immediately and send a redacted replacement. Repository history is not a safe secret store.