Security fixes target the latest published release.
Report vulnerabilities privately through support@xquik.com.
Do not open public issues for secrets, credential handling defects, private data exposure, or package supply-chain concerns.
We aim to acknowledge reports within 3 business days. We will coordinate a disclosure timeline after confirming the issue.
Security-sensitive areas include API key handling, request construction, response parsing, dependencies, generated code, and release metadata.