Do not open a public issue containing a vulnerability, exploit, credential, transcript, raw HID report, device serial number, local path, or user configuration.
Use GitHub private vulnerability reporting. If that control is unavailable, open a minimal issue requesting a private reporting channel without including technical details.
Security reports should identify the affected source revision and explain the local impact. No public binary release is currently supported. Hardware captures must be minimized and sanitized before sharing.
The maintainer will acknowledge a complete report, reproduce it where practical, and coordinate disclosure after a fix is available. Do not publish details before that coordination completes.