Do not open a public issue for a vulnerability, license value, entitlement token, signed download URL, customer file, or credential.
Use GitHub's private vulnerability-reporting flow:
https://github.com/VisualStandard/visual-standard-installer/security/advisories/new
Include the affected installer version, macOS and Node.js versions, reproduction steps, and the least-sensitive evidence needed to confirm the issue. Never include license keys, private signing material, bearer tokens, private runtime archives, or customer content.
General bugs that do not contain security-sensitive information may be reported at:
https://github.com/VisualStandard/visual-standard-installer/issues
Purchase, billing, and license-delivery questions are not security reports. Use the customer-support route published on the official Visual Standard website. Never include a complete license key in a GitHub issue or vulnerability report.