This project ships from main. Fixes land on main.
Please do not open a public issue for a security problem.
- Preferred: private report via GitHub Security Advisories ("Report a vulnerability" under Security).
Include what you found, how to reproduce it, and the impact. You will get an acknowledgement within a few days.
- Keep credentials in environment variables, never in committed files.
- Secret scanning and push protection are enabled on this repository.