Report vulnerabilities privately through GitHub's security advisory interface. Do not include project source, credentials, private assets, or recovery data in a public issue.
Supported releases are the latest GitHub release. Path traversal, symlink or
canonical-root escape, stale/external overwrite, partial transaction, project
code execution, dependency/source substitution, unbounded authored input, and
server control from the editor are security defects. See docs/THREAT_MODEL.md.