The latest commit on main is supported.
Please use GitHub private vulnerability reporting for security-sensitive reports.
Do not open a public issue for a suspected vulnerability. Include reproduction steps, impact, the affected provider path, and any suggested fix. Use fake credentials in examples and remove tokens, authorization headers, personal endpoints, and account details from logs or screenshots.
Security reports may cover credential discovery, authenticated network requests, redirect handling, provider responses, terminal rendering, command-line output, or repository automation.