Do not publish vulnerabilities, invitations, credentials, session files, private keys, provider IP addresses, container identifiers, or workload content in a GitHub issue.
Use GitHub's private vulnerability reporting for this repository. Include:
- A concise description and affected CLI version.
- Buyer or Provider surface.
- Reproduction steps using synthetic data.
- Expected and observed behavior.
- Security impact.
Do not test against another user's account, provider, workload, or capacity. Do not access customer data or attempt persistence.
Do not redeem it. Contact Punch support through the private channel that delivered the invitation and request revocation and replacement.
Only the latest published preview release receives security fixes during the invitation-only pilot.