Do not open public issues for sensitive security problems.
Never submit API keys, tokens, passwords, private credentials, personal data, or malicious scripts.
All dependencies should remain auditable through package.json, package-lock.json, licenses.production.json, and THIRD_PARTY_NOTICES.md.