Please do not file public issues for security-sensitive reports.
Report suspected credential exposure, authentication flaws, unsafe deployment defaults, or other security issues privately to the repository owner. Include the affected commit, file path, reproduction steps, and suggested severity when available.
If a secret is accidentally committed, rotate the secret first, then remove it from the repository and Git history before making any public release.