TimeFarm 0.2.x is a beta preview and is not yet a production-supported release. Security fixes are made on the latest source revision; older preview installers may not receive updates.
Do not open a public issue containing exploit details, credentials, personal data, or a working proof of concept. Use GitHub's private vulnerability reporting feature for this repository. Include the affected version, operating system, impact, reproduction steps, and any suggested mitigation.
If private vulnerability reporting is not visible, the repository owner must enable Settings → Security → Private vulnerability reporting before asking researchers to send sensitive details. Do not fall back to a public issue.
Never include Supabase service-role keys, access tokens, refresh tokens, local database contents, or customer work records in a report. A maintainer should acknowledge a complete report within seven days. Disclosure timing is agreed after impact and remediation are understood.