Do not open public issues containing credentials, tokens, private browsing data, or an exploitable vulnerability. Report security concerns privately to the project maintainers with reproduction steps, affected versions, and impact. Rotate any token included in a report.
The current pre-1.0 branch receives security fixes. Remote daemon exposure and third-party extension builds are unsupported.