Do not open public issues containing credentials, private repository URLs, or exploit details. Report a vulnerability privately to the maintainers with affected version, impact, and reproduction steps. Rotate any exposed GitHub token or secret immediately; repository history should be treated as compromised after a secret commit.
CodeGuardian intentionally treats its built-in detectors as advisory signals. Findings must be reviewed by a developer before remediation or pull-request publication.