Do not post secrets, full audit reports, or exploit details in public issues. Once this repository is published, use GitHub's private vulnerability reporting feature if enabled (Security → Report a vulnerability). If unavailable, open a minimal issue requesting a private contact channel without disclosing the vulnerability.
Version 0.0.x is the initial supported release line. Reports concerning path validation, backup integrity, terminal/HTML injection, or unintended modification are particularly relevant. Include a minimal synthetic reproduction, macOS version, and expected/actual behavior. Do not include real user/device data.
No security service or response-time guarantee is provided. Enable private vulnerability reporting before public release.