Report vulnerabilities privately through the repository's GitHub Security tab. Do not open a public issue containing credentials, exploit details, private repository data, or delivery payloads.
Supported releases are the current main commit and the latest tagged release. Security fixes are validated by the full test suite before merge.
Secrets belong in a runtime secret manager. Never commit GitHub App private keys, OAuth client secrets, webhook secrets, installation tokens, personal access tokens, .env files, or production delivery databases.