Security fixes target the current 0.1.x release line.
Do not open a public issue for a suspected vulnerability. Use the repository's private security advisory flow and include a minimal reproduction, affected version, and impact.
Do not include passwords, verification codes, saved-session material, browser data, private profile data, or personal identifiers in a report. If a report needs sensitive proof, describe the shape of the issue and wait for a maintainer response.
OrbitDiff is a local public-data tool. Security reports are especially useful for credential handling, local file permissions, SQLite access, package contents, command injection, and accidental data collection outside the documented public-only scope.