Report malicious translation packages, unsafe import behavior, path traversal, or accidental inclusion of private application data through GitHub Security Advisories. Do not attach secrets or private localization exports to public issues.
Security fixes target the current localization packages and workflow on the default branch. Translation contributions must remain data-only and must not introduce executable scripts or external download steps.