Do not open a public issue for suspected vulnerabilities, leaked credentials, download-integrity failures, or ways to bypass access controls.
Report security issues through a private GitHub security advisory when that option is available. Until then, contact the repository owner privately. Include affected versions, reproduction steps, impact, and any suggested mitigation.
Do not include live credentials, private user data, or third-party APK binaries in a report unless explicitly requested through the private channel.
Until the first stable release, only the latest commit on the default branch is supported.
Please report any suspected credential or sensitive-data exposure immediately.