Report vulnerabilities privately through GitHub Security Advisories. Do not open a public issue for an undisclosed vulnerability.
Pre-1.0 releases receive security fixes on the latest minor line. Waystone does not store credentials; reports should never include access tokens or private research data.