This repository is pre-1.0. Security fixes should target main.
Use a private GitHub security advisory or another private channel rather than filing a public issue for vulnerabilities.
Reports should avoid sharing real:
- dashboard URLs
- cookies
- tokens
- passwords
- provider keys
- private session transcripts
- local usernames or private file paths