Please do not disclose a suspected vulnerability in a public issue.
Report security concerns through GitHub's private vulnerability reporting for
DeliriumPulse/codetruss-cli.
Include the affected formula or CLI version, operating system, Homebrew version,
reproduction steps, and impact. Do not include provider keys, CodeTruss tokens,
receipt signing keys, repository secrets, or proprietary source code.
For an archive-integrity concern, include the release URL, observed SHA-256, and expected SHA-256. The current formula must never be changed to accept a mutable or unchecksummed download.