Verify before you run
Every release includes checksums, SBOMs, provenance and security review evidence.
Report privately
Do not open a public issue for an exploitable vulnerability. Follow the repository security policy and contact the maintainers privately.
Package verification
Match SHA-256 checksums, inspect Authenticode status and download only from the official GitHub Release.