Security fixes are provided for the latest minor release while the project is pre-1.0.
Please use GitHub's private vulnerability reporting for this repository. Do not attach real recipient documents or credentials. Provide a synthetic reproducer, affected version, platform, and expected versus observed behavior.
Run BatchSeal with least privilege against a copy or read-only mount of the outbound
batch. A passing report does not prove that image-only content, handwritten content,
or an unsupported embedded object is safe. Review docs/threat-model.md before using
the tool in a regulated workflow. Reports retain recipient IDs and relative filenames,
so use opaque values or protect the report directory accordingly.