Security fixes are applied to the latest version on the main branch.
Please do not open a public issue for a vulnerability that could expose invoice data, bypass local protections, or compromise an iCloud container. Use the repository’s Security → Report a vulnerability flow so the report remains private while it is investigated.
Include the affected commit, reproduction steps, impact, and any suggested mitigation. You should receive an acknowledgment within seven days.
Never attach real invoices, device console archives, provisioning profiles,
signing certificates, or Config/Local.xcconfig to an issue. Redact bundle IDs,
iCloud container identifiers, file paths, record IDs, and customer information
from diagnostic output.