If you discover a security issue, please report it responsibly:
- Do not open a public GitHub issue for security vulnerabilities.
- Email chad.hendren@gmail.com with details and steps to reproduce.
- Allow up to 72 hours for an initial response.
- Never commit API keys, tokens, passwords, or
.envfiles. - Use environment variables or your platform's secret manager.
- Rotate any credential that may have been exposed.
Security fixes are applied to the default branch (main or master).