Send sanitized vulnerability reports privately to eric@elpete.com. Do not put credentials or private data in public issues. Rotate compromised keys through the storage provider. Maintainers coordinate fixes and disclosure; no response SLA is promised. Security fixes target the latest stable release.