Please do not report suspected vulnerabilities in a public issue.
Use GitHub's private vulnerability reporting for this repository when it is available. Otherwise email mo@codelit.io with the repository name, affected version, reproduction steps, and impact.
Never include production credentials, customer data, access tokens, or other sensitive material in a report. Codelit will acknowledge a complete report as soon as practical and coordinate disclosure after a fix is available.