Do not open a public issue containing credentials, cookies, personal memo content, or private database records.
Please report security issues privately to the maintainer through GitHub's private reporting channel when available.
High-priority reports include:
- bypasses that create active memory without review lineage;
- secret or raw-note leakage into logs or persistent derived storage;
- forged evidence metadata crossing the trusted staging boundary;
- unsafe handling of flomo authorization or signing material.
Before reporting, remove personal note text and replace credentials with inert placeholders.