Please do not open a public issue for a suspected vulnerability. Use the repository's Security tab to open a private GitHub Security Advisory and include:
- affected commit or version;
- macOS and terminal version;
- the smallest reproducible command and redacted output;
- expected impact and whether a backup was created;
- a proposed fix, if available.
Do not attach private terminal configurations, tokens, usernames, hostnames, or personal filesystem paths. Maintainers will acknowledge a complete report when available, investigate it privately, and coordinate disclosure after a fix is ready. There is no guaranteed response time or bug bounty.
Security fixes target the current default branch. Older snapshots are not maintained separately.