Report vulnerabilities through the repository's private GitHub Security Advisory flow. Do not open a public issue when tokens, private repository data, unsafe network handling, or generated reports may be exposed.
Include the affected version, reproduction steps, expected behavior, and impact. Use synthetic or redacted values only. Until the first stable release, only the latest beta release is supported.