Security and privacy fixes target the current main branch and the newest
GitHub Release. Older pre-releases and historical tags are not maintained.
Use GitHub's Security → Report a vulnerability flow to submit a private report. Do not open a public issue for credentials, path-containment failures, silent overwrite, unintended uploads, private-paper exposure or another issue that could place user data at risk.
Include only the minimum redacted reproduction needed to identify the affected
version, operation and failure boundary. Do not attach paper PDFs, generated
notes, Zotero databases, Vault contents, API keys, usernames or raw local
paths. If a doctor --support-bundle archive is relevant, review it before
sharing.
You should receive an acknowledgement within seven days. Publication and fix timing depend on severity and reproducibility; please allow coordinated remediation before public disclosure.