Please report security issues privately to the project maintainer instead of opening a public issue.
Include:
- a clear description of the issue
- affected versions or commits
- reproduction steps or proof of concept
- impact assessment
Sensitive material for this project includes:
- relay client private keys
- pairing codes and bridge credentials
- WebSocket bearer tokens
- platform signing keys and local signing configuration
Do not include active secrets in bug reports, issues, screenshots, or pull requests.