Do not disclose vulnerabilities in public issues or pull requests.
Report vulnerabilities through GitHub private vulnerability reporting for
yaffle-dot-dev/cli, or email security@yaffle.dev. Include affected versions, reproduction steps,
impact, and any suggested mitigation. Do not include live customer credentials or Terraform state.
The latest v0.1 release receives security fixes. We will acknowledge a report as soon as practical, coordinate remediation and disclosure with the reporter, and publish a security advisory when users need to take action.