Do not open a public issue for a suspected vulnerability.
Use GitHub's private vulnerability reporting from this repository's Security tab (Report a vulnerability). Include the affected version or component, impact, minimal reproduction, and any known mitigations. Do not include live credentials or private source code.
Security fixes are applied on a best-effort basis to the latest release and the
latest code on main.
Upload path accepts only att_ API keys. Temporary GitHub App user tokens are
used solely at human enrollment and must never be logged or persisted.