Please do not report vulnerabilities in public issues.
Use GitHub's private vulnerability reporting feature for this repository. Include a clear description, reproduction steps or proof of concept, affected versions, and any suggested mitigation. We will acknowledge valid reports as soon as practical and coordinate disclosure after a fix is available.
For local development, keep all credentials in .env files. Never commit API keys, OAuth secrets, database URLs containing passwords, or user data.