This repository does not publish official release artifacts. Security fixes are made on the current main branch.
Use GitHub Private Vulnerability Reporting for this repository. Do not open a public issue for suspected token disclosure, cache exposure, or query-limit bypass.
Reports are acknowledged within five business days. Token exposure is treated as urgent. Include reproduction steps, affected versions, impact, and any suggested mitigation. Coordinated advisories will be published when users must take action.
Never include a real STRATZ token, private player data, cache database, or fetched restricted schema/constants in a report.