Security fixes are provided for the latest published Tokenfold release. Upgrade to the newest patch release before reporting behavior that may already be fixed.
Please report suspected vulnerabilities privately through GitHub Security Advisories. Do not open a public issue for an unpatched vulnerability.
Include the affected version and surface, reproduction steps, expected impact, and any known workarounds. Do not include real credentials, secrets, or sensitive customer payloads. You should receive an acknowledgement through the advisory within seven days.