Preview software; no security certification or guaranteed response SLA. Do not deploy with production mutation rights or expose as a public multi-user service.
Report vulnerabilities using the repository's private vulnerability-reporting feature when enabled. If unavailable, request a private contact method without disclosing the vulnerability in a public issue. Never publish connection strings, access keys, session cookies, raw XEL, database dumps or state/.keys. Rotate exposed credentials and preserve sanitized incident evidence.
The project does not invent a maintainer email or security contact. Enable private reporting on your GitHub repository before inviting reports.