Security disclosure

Report vulnerabilities with enough detail to reproduce the issue without sharing unnecessary cluster secrets.

What to report

Credential exposure, release verification bypasses, hostile-data rendering bugs, unsafe egress, and webview boundary escapes.

What to include

Version, operating system, reproduction steps, expected behavior, actual behavior, and redacted evidence.

What not to include

Do not send raw kubeconfigs, live tokens, private keys, or production cluster secrets.