Security fixes are applied to the latest revision of the main branch.
Do not open a public issue for vulnerabilities or exposed credentials. Use the repository's private security advisory feature to report:
- affected file or component;
- reproduction steps;
- expected impact;
- suggested mitigation, if available.
If a credential is exposed, revoke or rotate it before removing it from Git history.