Security fixes are provided for the latest released version of Loadout. Before
the first public release, fixes are made on the main branch.
Please do not open a public issue for a suspected security vulnerability. Use GitHub's private vulnerability reporting for this repository instead.
Include a clear description of the issue, reproduction steps, affected versions, and any potential impact. You will receive an acknowledgement within seven days. Please allow time for a fix and coordinated disclosure before sharing details publicly.
Reports are especially welcome for vulnerabilities involving secret exposure, unsafe repository traversal, unintended command execution, service-connectivity checks, the installer, release artifacts, or GitHub Actions workflows.