The latest released VibeSpec plugin line receives security fixes. Older plugin lines are not maintained with parallel security patches; upgrade to the latest release when a fix is published.
Use GitHub private vulnerability reporting for suspected vulnerabilities. Include the affected version, impact, reproduction steps, and a minimal proof of concept when available.
Do not open a public issue containing secrets, credentials, private SOT data, or local workstation paths.
If a tracked file or Git reference accidentally discloses a local path, report the file or reference that contains it without repeating the path value. Use a neutral placeholder in any description or reproduction material.