Please do not report security vulnerabilities through public GitHub issues.
Follow Ramp's security reporting guidance to report a vulnerability privately. Include the affected SDK version or commit and the minimum information needed to reproduce the issue. Do not include live credentials, access tokens, payment data, or customer data.