Do not open a public issue for a security problem.
Report it privately through GitHub's private vulnerability reporting on the affected repository. If that is not available to you, contact us through https://duxpace.no.
Include what you found, how to reproduce it, and what an attacker could do with it. We will confirm receipt, tell you what we found, and let you know when a fix ships.
Credentials belong in a password vault or in a secret store, never in a repository, a document, a wiki or a whiteboard. If a secret does end up committed, rotate it first and clean up the history second. Removing the file is not enough, history keeps it.
The products are pre-release. Only the current master of each repository is maintained.