Do not include auth.json, Keychain payloads, access tokens, refresh tokens,
account identifiers, or staging Codex homes in issues or logs.
Report vulnerabilities privately to the maintainers. Until a private contact is published, open an issue containing no exploit details and request a secure reporting channel.
Supported security updates target the latest revision of main only.