Security fixes are released for the latest version.
Use GitHub's private vulnerability reporting. IdentityLint never requests, reads, prints, or stores GitHub tokens, SSH private keys, credential-helper output, or environment values. Reports must not include those materials.
IdentityLint is a local consistency guard, not an authentication boundary. Git and GitHub remain the authorities that authenticate commits and network operations.