Security fixes are applied to the latest released minor version.
Please do not open a public issue for a suspected vulnerability involving credential exposure, command execution, path traversal, or disclosure of private repository data.
Use GitHub's Report a vulnerability flow in the Security tab of this repository. Include reproduction steps, affected versions, impact, and any suggested mitigation. The maintainer will acknowledge a complete report as soon as practical and coordinate disclosure after a fix is available.
BlameTrail does not need write access to analyzed repositories. Tokens used for private repositories should be restricted to read-only contents, pull requests, and issues.