For a private report, use GitHub Security Advisories rather than a public issue.
Do not disclose credentials, private keys, or tenant data in issues. Report a suspected vulnerability privately to the maintainers with reproduction steps, impact, and affected versions. Rotate any credential that appears in logs or chat immediately.
Security-sensitive changes must preserve tenant isolation, secret redaction, artifact access controls, and custom-code permission boundaries.