Security fixes target the latest version published on npm. Update before reporting an issue that may already be fixed.
Email security@nibras.co. Do not open a public issue or discussion.
Include, when applicable:
- A concise description and potential impact
- Affected package, OpenCode, and Node.js versions
- Reproduction steps or a proof of concept
- Relevant logs with API keys, prompts, and personal data removed
You should receive an acknowledgment and a request for any missing details. Please allow time for investigation and a release before public disclosure. If the report is not security-sensitive, use the normal issue templates instead.