This project is in preview. The latest preview line receives best-effort security fixes.
If GitHub private vulnerability reporting is enabled, use it.
If it is not enabled, open a minimal issue asking for a secure contact path. Do not include exploit details, secrets, tokens, private keys, or sensitive data in a public issue.
This policy covers the source code and npm packages in this repository.
- The tools are local-first developer utilities.
- They do not send telemetry by default.
- They must not capture credentials.
- They must not require secrets for basic local usage.
- Do not paste secrets into examples, issues, fixtures, or reports.
- These tools are not a security audit, compliance audit, legal review, or certification product.
This is a preview, solo-maintained project. Security reports are handled on a best-effort basis and do not include a formal SLA.