DevConsole is for internal/debug builds only. Do not enable it in production variants.
Only the latest 1.x release line receives security fixes. Development snapshots are not supported.
Do not file public issues for suspected credential exposure, production inclusion, authentication bypass, or remote code execution. Contact the maintainers through the repository's private security-reporting channel and include a minimal, redacted reproduction. We acknowledge reports within five business days and provide a status update within ten business days.
We validate reports privately, assign severity, coordinate an embargo when appropriate, release a signed fix, and request a CVE for eligible issues. Production inclusion or credential exposure is treated as critical. Release artifacts must be signed and accompanied by an SBOM/provenance record.