Report vulnerabilities privately through GitHub Security Advisories for
gnolith/alembic. Do not open a public issue for suspected vulnerabilities.
The supported line is 0.1.x on Node.js 22+. Security fixes are coordinated by the sole maintainer. Alembic accepts selectors, never secret values; reports containing credentials must be redacted before submission.