Use GitHub's private vulnerability reporting for the repository when enabled. Do not include credentials, private note text or active callback URLs in public issues. If private reporting is not available, contact mkdev through mkdev.me to arrange a private report.
Maintainers should enable private vulnerability reporting before publishing this repository. Reports about the Basecamp SDK or Obsidian itself should also be sent to the upstream project when appropriate.