Security fixes are applied to main until the project begins versioned releases.
Do not open a public issue for a suspected vulnerability. Use GitHub private vulnerability reporting for this repository after it is published, or contact the repository owner through the email shown on the GitHub profile.
Include the affected component, reproduction steps, impact, and any suggested mitigation. Do not include real customer data, credentials, exploit payloads against third-party systems, or authorization-sensitive material.
The repository is a reference implementation, not authorization to test systems. Active validation must only run against explicitly authorized targets.