Report vulnerabilities privately through the repository's GitHub security advisory page. Do not open a public issue for an undisclosed vulnerability.
The delivery-proof token is deterministic public deployment metadata, not a secret, signature, or authentication credential. Preview-origin environment values are display evidence only. Applications must make authorization and routing decisions from trusted server-side state.
Security fixes are supported on the latest release. Include affected versions, reproduction conditions, and impact in a report. Do not include live credentials or private deployment data.