Please do not open a public issue for a suspected vulnerability or include real credentials, account IDs, email addresses, terminal output, or customer data in an issue.
Use the repository's Security tab to open a private security advisory. Include the affected version or commit, the impact, and the smallest safe reproduction you can provide. Maintainers will respond when available; this community project does not promise a specific response time.
Security fixes target the latest commit on the default branch. Older commits and forks are not maintained.
The operator owns the AWS account, IAM Identity Center application and group assignments, Bedrock access, costs, backups, updates, and deletion. Review changes before deploying them and use a separate non-production AWS account for evaluation.