Security fixes are applied to the latest code on main. Until a stable release exists, older snapshots are not maintained separately.
Do not open a public issue for a suspected vulnerability or accidental secret exposure.
Use GitHub's private vulnerability reporting feature for this repository. If it is unavailable, contact a maintainer privately using the contact method on the repository owner's GitHub profile. Include reproduction steps, affected versions, impact, and any suggested mitigation. Avoid including real credentials or sensitive user data.
Maintainers should acknowledge a report within seven days and provide a status update after triage. Disclosure timing will be coordinated with the reporter when practical.
Demo tapes execute shell commands. Treat contributed tapes and fixtures as code: review them before running, use isolated environments for untrusted contributions, and never embed credentials in authored or generated media.