Please do not open a public GitHub issue for a suspected security vulnerability.
Report security issues privately through the repository's configured GitHub security reporting channel. Include:
- affected version or commit
- operating system and environment
- clear reproduction steps or a proof of concept
- expected impact
- any suggested mitigation
Please avoid including API keys, personal data, screenshots containing secrets, or other sensitive information in the report.
Security fixes are prioritized for the latest release on the default branch. Older versions may not receive backported fixes.
Relevant security reports include credential handling, backup/restore, unsafe file access, provider request handling, and other vulnerabilities that can expose or modify user data.