Report security issues privately to engineering@kuest.com.
Include:
- affected crate version
- reproduction details
- impact assessment
- any suggested mitigation
- Do not open public issues for credential leaks or signing flaws.
- Rotate any exposed builder credentials immediately.
- Publish fixes only after the issue is triaged and a patched release is prepared.