Please do not open a public GitHub issue for security reports.
Instead, email the maintainers at security@tokenoodle.com with:
- a description of the vulnerability and its impact;
- minimal reproduction steps;
- affected versions and platforms.
You will receive an acknowledgement within 72 hours and a resolution timeline within 14 days. Credit is given in the release notes unless you prefer otherwise.