Please do not open a public issue for a potential vulnerability. Email security@boringcache.com or use GitHub private vulnerability reporting.
Include the affected version, expected impact, and enough reproduction detail for us to investigate. Do not include live credentials, private keys, customer data, or production configuration.
Only the latest published release is supported. Security fixes are normally shipped in a new release rather than backported.
Reports about WireGuard key handling, SSH host verification, generated network configuration, command execution, or release integrity are welcome.