Please do not open public issues for security vulnerabilities.
Report vulnerabilities privately by contacting the maintainers with:
- a clear description of the issue
- affected versions / files
- reproduction steps or proof of concept
- potential impact
You can use one of these private channels:
- GitHub Security Advisories (preferred)
- Private email to project maintainers
- We will acknowledge reports as soon as possible.
- We will triage severity and scope.
- We will provide a fix or mitigation plan.
- We will coordinate disclosure timing with the reporter.
This project is local-first and often handles project metadata in local files. Keep sensitive data out of tracked files and prefer environment variables or local-only config.