Report a suspected vulnerability privately through GitHub Security Advisories after the repository is published. Do not include real credentials, private traces, or confidential source files in a report.
Security-sensitive areas include project-root containment, symlink behavior, proposal hash verification, rollback integrity, and unintended execution of stored content.
Only the latest released version receives security fixes during the initial project phase.