Brev is pre-1.0 and not yet approved for production Peppol transmission. Security and conformance issues should nevertheless be reported privately through GitHub Security Advisories for beint-no/brev.
Do not open a public issue for entity expansion, resource-limit bypasses, document-confusion vulnerabilities, validation bypasses, signature or certificate issues, or fixtures containing confidential invoice data.
Supported security fixes apply only to the current target release on the main branch. Historical Peppol releases are outside the support policy.