Security fixes are applied to the latest version on the default branch.
Please use GitHub's private vulnerability-reporting flow for vikky781/codebase-cartographer when it is available. If it is not available, open a minimal issue that requests a private contact channel and does not include sensitive source code, credentials, tokens, or repository history.
CodebaseCartographer is designed to analyze only user-approved local repositories. Reports involving path traversal, unintended code execution, data exfiltration, unbounded resource use, cache handling, or unsafe Git invocation are especially useful.