Security fixes are applied to the latest version on main and the latest GitHub Release.
Please do not open a public issue for a suspected vulnerability, especially one involving local WorkBuddy sessions, the plugin event spool, or release artifacts. Use GitHub private vulnerability reporting instead.
Include a clear reproduction, affected version, impact, and any proof of concept that does not expose someone else's data. We will acknowledge a report within seven days and coordinate a fix before public disclosure.