Please report security vulnerabilities privately through GitHub Security Advisories / Private Vulnerability Reporting when available. Do not publish exploitable details, real credentials, customer data, or destructive proof-of-concept material in a public issue.
Include the affected component, impact, reproduction conditions, and a minimal non-destructive proof.
Changes involving authentication, authorization, tenant/company isolation, secrets, external providers, webhooks, payments, files, AI/tool actions, approvals, research data, or persistent state should include targeted negative and boundary tests.
Never commit production credentials, API keys, OAuth secrets, database passwords, private certificates, real session tokens, or customer exports.
Security claims must follow repository evidence. Source-level controls, focused tests, evaluations, and production certification are different evidence levels.
Good-faith testing should use synthetic/test data, avoid service disruption, minimize access to data not owned by the researcher, and allow reasonable time for remediation before public disclosure.