Security

Verify before you run

Every release includes checksums, SBOMs, provenance and security review evidence.

01

Report privately

Do not open a public issue for an exploitable vulnerability. Follow the repository security policy and contact the maintainers privately.

02

Package verification

Match SHA-256 checksums, inspect Authenticode status and download only from the official GitHub Release.