When GitHub's Report a vulnerability control is available in the
repository's Security area, use it to open a private report. Otherwise, report
suspected vulnerabilities, package substitution, or credential exposure
privately to support@sixtyfold.dev with SECURITY in the subject.
Include the affected package and version, reproduction details, potential impact, and any evidence you can safely share. Do not include secrets or personal data that are unnecessary to investigate the report.
Please do not open a public issue. We will acknowledge your report, share material updates, and coordinate disclosure with you.