Report suspected vulnerabilities through GitHub Security Advisories. Do not publish credentials, tokens, exploit details, private repositories, customer data, or Starcat private data in a public issue.
Include the affected version or commit, environment, reproduction steps, and expected impact. You should receive an acknowledgement within seven days.
Security fixes are provided for the latest published stable release or the current default branch when the project has not published a stable release.
Before publishing this repository, replace this section with its real authentication, network, storage, update, dependency, and secret-handling boundaries.