Security fixes are applied to the latest version on the default branch.
Do not open a public issue for suspected vulnerabilities or accidental sensitive-data exposure.
Use a private GitHub security advisory when available. Include the affected command, expected behavior, observed behavior, and a minimal synthetic example. Never include private keys, PINs, raw production reports, or full device identifiers.
UKey Detector performs local, read-only inspection. It must not export key material, request PINs, sign data, or change certificate stores, drivers, services, registry values, or USB power state.