Security fixes are applied to the latest main branch.
Do not open a public issue for a vulnerability, a real secret, or session data that may contain sensitive information. Report it privately to blain3white@gmail.com with:
- a concise impact description;
- reproduction steps or a minimal safe proof of concept;
- the affected version or commit; and
- suggested remediation, if known.
We will acknowledge a report within seven days and coordinate a fix before public disclosure when practical.
Team Memory redacts common secret patterns before persistence, but redaction is not a substitute for human review. Treat imported sessions as potentially sensitive, keep raw evidence out of public repositories, and review every generated fact before publishing it to a shared Memory Git repository.