Security fixes are applied to the default branch of this repository.
Please do not open a public issue for security problems.
Report privately via GitHub Security Advisories for this repository (Security → Advisories → Report a vulnerability), or contact the owner (@ztel42) with enough detail to reproduce.
We aim to acknowledge reports within 7 days and share a remediation plan when feasible.
This repository aims to keep:
- Dependabot security updates / vulnerability alerts enabled when available
- Secret scanning enabled when available for the plan/visibility
- No hardcoded secrets; use environment variables or a secret store
- Dependency pins kept current for known Critical/High CVEs
Last aligned: Sat Sep 19, 2026 ET