Use GitHub private vulnerability reporting for confidential reports. Do not put credentials, private keys, customer data, exploit details or persisted runtime state in a public issue or pull request.
Run under a dedicated unprivileged service identity. Control uses a private Unix socket; authorized local clients need the service OS identity. State/socket parents are private directories, and keys, databases and sockets have restricted permissions. One process owns each state directory through its process lock.
Keep credentials and private material outside the repository. Protect backups with the same confidentiality controls as live state. Retain operation IDs when retrying; use a new generation for an intentional replacement. Resolve durable terminal/attention states before retrying uncertain external mutations.
Provider/CA clients validate HTTPS and use bounded deadlines and response bodies. Store schema and wire-version changes require an explicit upgrade plan. The checked-in lockfile pins dependencies; review current advisories when updating it.