Use GitHub private vulnerability reporting for security issues. Do not open a public issue with vulnerability details. Never include API keys, authenticated CDP URLs, cookies, checkpoint contents, or customer data in a report, example output, screenshot, or log.
Examples read credentials only from BRAWSR_API_KEY and never print them. Use a
short-lived development key and revoke it after live qualification.
The Stagehand example runs with its AI-provider path disabled. CI blocks high-severity dependency advisories; lower-severity transitive advisories remain tracked upstream until a compatible fix is available.