Trust / Security

Security policy

Report a vulnerability

Please do not disclose an exploitable vulnerability in a public issue. Use a private GitHub Security Advisory and include the affected version, edition, operating system, minimal reproduction, impact, and sanitized logs.

What to protect

Reports involving process execution, path traversal, state injection, installer behavior, runtime isolation, or secret exposure are especially useful. Do not upload credentials, certificates, private keys, or malicious samples containing real user data.

Release verification

Release artifacts are published through GitHub Releases with a SHA-256 manifest. Verify the checksum before installation and review the release notes.

Machine-readable policy

The public machine-readable policy is available at /.well-known/security.txt.