The project supports the latest release on the default branch during the pre-1.0 period.
Use GitHub's private vulnerability reporting feature when the repository enables it. If that option is unavailable, contact a maintainer through a private channel listed on their GitHub profile.
Include the affected version, operating system, provider CLI versions, impact and a minimal reproduction. Remove credentials, private source code and raw provider transcripts.
Do not open a public issue until a maintainer confirms that disclosure is safe. We will acknowledge a report, assess severity and coordinate a fix and disclosure timeline.