Report a vulnerability privately using the repository's Security → Report a vulnerability feature when available. If it is unavailable, contact the maintainer through their GitHub profile to arrange a private channel. Do not include credentials, source addresses or personal information in a public issue.
This project is a local batch CLI. It has no hosted service or authentication system. Its inputs are official public downloads or files supplied by the user. Keep dependency versions reviewed, and treat unfamiliar local input files as untrusted. Cache checksums detect changes; they do not authenticate a publisher.
Security fixes target the current default branch. There is no support SLA.