Security fixes are provided for the latest released minor version of DocsWatch.
Report vulnerabilities through GitHub private vulnerability reporting. Do not open a public issue for an undisclosed vulnerability.
Include affected versions, a minimal reproduction, expected impact, and any known mitigations. Avoid including credentials, tokens, or private repository content that is not necessary to reproduce the problem.
DocsWatch parses repository-controlled files. Reports involving path traversal, unsafe symlink handling, unintended code execution, or disclosure of scanned content are especially useful.