If you believe you have found a security vulnerability, please:
- Do not open a public issue.
- Report privately via one of these methods:
- GitHub Security Advisories (preferred)
- Contact form - select "Security" as the subject
- We will acknowledge receipt within 72 hours and coordinate a fix and disclosure.
We recommend running govulncheck and keeping dependencies up to date.