Please report suspected vulnerabilities through GitHub's private vulnerability reporting. Do not open a public issue for a security-sensitive finding.
Include the affected version, macOS version, filesystem type, reproduction steps, and sanitized output. Never include credentials, private file names, or volume contents.
The project is maintained on a best-effort basis. Confirmed vulnerabilities will be assessed and fixed before public disclosure when practical.