Do not open public issues for security vulnerabilities.
Report privately to: security@example.com
| Version | Supported |
|---|---|
| Latest | ✅ |
- Never commit secrets, keys, or environment variable values
- Use
appsettings.*.local.jsonfor local secrets (gitignored) - Review PRs for accidental secret exposure
- Run CodeQL analysis before merging security-sensitive changes