Security fixes are made against the current main branch. Older commits and forks may not receive updates.
Please do not report security vulnerabilities in a public GitHub issue. Use the repository's Security tab and select Report a vulnerability to submit a private report.
Include:
- a clear description of the issue and its impact;
- affected files, versions, and configuration needed to reproduce it;
- safe reproduction steps or a proof of concept; and
- any proposed mitigation, if available.
Do not include a real Stash database, media files, private paths, credentials, or personally identifying metadata in a report. We will acknowledge reports, assess their impact, and coordinate disclosure through GitHub's private vulnerability-reporting flow.