Do not commit credentials, user home paths, live configuration, or secret material.
Product environment variables use the WORKFORCE_ prefix. .env files are local-development only and are not a desktop credential store.
Until a public disclosure process is published, treat suspected vulnerabilities as private reports to the maintainers. Do not file public issues that include exploit details or live secrets.