Security fixes are applied to the latest release.
Please use GitHub private vulnerability reporting. Do not open a public issue for a suspected vulnerability.
Include the affected version, operating system, a minimal reproduction, and the impact. Remove tokens, credentials, private command output, and personal data before submitting.
Winnow stores full command output locally for recall. Treat the Winnow home
directory (~/.winnow by default) as sensitive and protect it with the same
care as local logs and shell history.