Report a vulnerability privately to the maintainer by GitHub private vulnerability reporting, or by opening a draft advisory. Do not open a public issue for an exploitable flaw.
This mod stores no secrets and processes no personal data. The vendored
CBA headers in include/ are the only third-party code in the repository;
they are tracked and pinned in include/x/cba/README.md.
The repository has no remote CI secrets beyond GitHub Actions tokens.