Please do not report vulnerabilities in a public issue.
Use GitHub's Security → Report a vulnerability flow for this repository. Include the affected version, impact, reproduction steps, and any suggested mitigation. Remove credentials, private kubeconfigs, certificates, tokens, and unnecessary identifying network information before submitting the report.
This is an early-stage project that runs as root and changes host networking, services, and Kubernetes state. Security reports involving command execution, unsafe file handling, privilege boundaries, release integrity, or destructive cleanup are especially useful.