Security fixes are applied to the latest release and the default branch.
Use GitHub's private vulnerability reporting for this repository. Do not include real client files, secrets, personal information, or private links. A minimal synthetic reproduction is preferred.
Expect acknowledgment within five business days. We will validate the report, agree on disclosure timing, prepare a fix and tests, and credit the reporter unless anonymity is requested.
Security-sensitive areas include archive path handling, symbolic links, secret detection, private-data leakage, unsafe extraction, and unexpected network access.