Please report suspected Cedra vulnerabilities privately to
support@imgil.dev. Include the affected version, the execution path or
input involved, and a minimal reproduction when it is safe to provide one.
Please do not publish details or an exploit before Manuel Gil has had a reasonable opportunity to investigate and release a fix. Reports involving privileged execution, software acquisition, package removal, or release artifacts should identify whether the behavior was observed from an installed package or a source checkout.