Security fixes are applied to the latest version on the default branch. Older plugin versions may not receive fixes.
Please use GitHub's private vulnerability reporting or Security Advisory workflow once this repository is public. Do not open a public issue for an undisclosed vulnerability.
Include:
- affected plugin and version;
- reproducible steps and impact;
- the smallest relevant log or configuration excerpt, with credentials removed.
Do not include API keys, access tokens, private customer data, or complete .env files. The repository does not require credentials for its deterministic validation suite.