Please do not disclose vulnerabilities in public issues. Use GitHub's private security advisory reporting for this repository. If private reporting is unavailable, contact a Chaitin maintainer through an official Chaitin security channel and include the affected plugin/version, reproduction steps, and impact. Do not include live credentials or sensitive customer data.
The latest release is supported. Maintainers will acknowledge a complete report, coordinate remediation and disclosure, and publish fixed plugin packages when needed.