Please report vulnerabilities through the repository's private GitHub security advisory workflow. Do not open a public issue containing credentials, provider responses, or other sensitive information.
Only the latest version on the main branch is supported. API keys must be
provided through environment variables and must never be committed to the
repository, fixtures, logs, or bug reports.