Security fixes are made on the current main branch. Before the first hosted release, there is no separate maintained release line.
Do not create a public issue for a suspected vulnerability. Once the GitHub repository exists, use its private security-advisory reporting channel. Until then, contact the repository owner through the private channel they provide when publishing the repository.
Include a minimal reproduction, affected version or commit, impact and a safe way to verify the report. Do not attach real process listings, tokens, full command lines, home paths or screenshots containing private services.
SocketSage listens only on 127.0.0.1, exposes GET-only endpoints, uses local lsof and ps reads, and has no account, telemetry, remote host support, packet capture or process-control endpoint. A behavior outside that boundary is especially relevant to report.