Security fixes are applied to the latest release and the current main branch.
Do not open a public issue for a suspected vulnerability or for a prompt, asset, or log containing sensitive data.
Email 1515065785@qq.com with:
- a concise description of the issue and its impact;
- affected files, commands, or workflow;
- reproduction steps or a minimal proof of concept;
- any suggested mitigation;
- whether you need coordinated disclosure.
You should receive an acknowledgement within seven days. Please allow time for validation and a fix before publishing details.
Useful reports include unsafe file handling, command injection, path traversal, accidental data disclosure, dependency risks, and repository automation that grants excessive permissions. Quality disagreements about generated visuals belong in the bug tracker, not the security channel.