Please report security issues through GitHub private vulnerability reporting. Do not open a public issue for authentication, hidden-information, token, or data-exposure vulnerabilities.
Include the affected route or command, reproduction steps, expected impact, and any suggested mitigation. Reports will be acknowledged as soon as practical. There is currently no bug-bounty program.
Only the latest commit on main is supported while Rill remains pre-release.