Security fixes are provided for the latest published release. Before the
first release, reports should target the current main branch.
Please do not open a public issue for a suspected vulnerability. Use GitHub private vulnerability reporting so the report and any supporting material remain confidential.
Include the affected version or commit, deployment configuration, impact, reproduction steps, and any suggested mitigation when available. Do not include live credentials, ServiceAccount tokens, customer data, or other secrets in the report.
Public disclosure should wait until a fix or mitigation is available and a coordinated disclosure date has been agreed.