Do not report vulnerabilities through a public issue. Contact the Minmo engineering team privately and include the affected SDK version, request path, impact, and a minimal reproduction when possible.
Never include a live Partner API key, authorization header, payment credential, private key, or personally sensitive data in a report. Revoke and rotate any credential that may have been exposed.