Security Policy Reporting Vulnerabilities
Please report security vulnerabilities privately rather than through public GitHub issues.
Include:
Description of the vulnerability Steps to reproduce Potential impact Relevant safe evidence
Never include passwords, API keys, database credentials, or other secrets.
Secrets
Production credentials must be stored in environment variables and must never be committed to the repository.