redacted scrubs secrets from tool output, so a missed secret (false negative)
or a crash that lets raw output through is a security issue, not just a bug.
Please report privately, not in a public issue: open a security advisory.
Include a synthetic example (never a real secret), the expected vs actual
redaction, and your version (redacted --version).
In scope: missed secrets, fail-open on malformed input, panics, and pattern bypasses. Out of scope: over-redaction (false positives), tracked as normal bugs.
The latest released version receives fixes.