Report vulnerabilities through GitHub private vulnerability reporting. Do not publish exploit details, credentials, indexed repository content, or embedding request payloads in an issue.
The index is derived workspace data, not a security boundary. Reports involving workspace escape, symlink traversal, credential persistence, unintended network access, or indexed secret exposure are security issues.
The project is pre-release. Security fixes target main and the most recent npm prerelease after publishing begins.