Report authentication bypasses, SSRF, unsafe URL handling, cache poisoning, or secret exposure through GitHub Security Advisories. Do not publish API keys, database contents, probed private URLs, or production logs in an issue.
Security fixes target the current default branch and latest deployed version. Runtime secrets must be injected through environment variables or Fly.io secrets and must never be committed.