Please report security vulnerabilities privately through GitHub's Security Advisories. Do not open a public issue.
Include the app version, macOS version, and steps to reproduce.
We aim to acknowledge reports within 3 business days and provide a status update within 7 days. If the issue is confirmed, we'll work on a fix and credit you in the release notes unless you'd prefer otherwise. If we decline, we'll explain why.