| Version | Supported |
|---|---|
| 1.x | ✅ |
If you discover a security vulnerability, please report it responsibly:
- Do not open a public issue
- Email the maintainer or use GitHub's private vulnerability reporting
- Include steps to reproduce the issue
- Allow reasonable time for a fix before public disclosure
This project handles GitHub tokens and API keys via environment variables. Please report any issues related to:
- Token or credential exposure
- Unsafe handling of secrets
- Dependency vulnerabilities
We aim to acknowledge reports within 48 hours and provide a fix or mitigation within 7 days.