Security fixes are applied to the latest published release.
Use the repository's Security tab to submit a private GitHub Security Advisory. Do not disclose a vulnerability in a public Issue before a fix is available.
Never paste any of the following into an Issue, Discussion, Pull Request, screenshot, or CI log:
- Feishu/Lark app secrets or access credentials.
- Document, whiteboard, Base, or message resource tokens.
- Production business data or customer information.
- Browser cookies, passwords, or local credential files.
Include a concise description, affected version, reproduction steps using neutral data, and the expected security impact. You should receive an initial response through GitHub within seven days.