# Security Report vulnerabilities privately through the repository security contact. Never paste real credentials or private HAR content into a public issue. Descriptions, examples, URLs and exchanges are hostile inert data. API Tools must not execute generated text or resolve external references. Deploy with the same-origin CSP. Security fixes target the current release.