Do not file public issues containing credentials, tokens, private source code, local paths, or support bundles.
Security reports should include the affected Sunsetz version, operating system, reproduction steps, expected impact, and whether the issue reproduces with SUNSETZ_ACP=mock. Remove secrets before sharing diagnostics.
Use a private GitHub security advisory. Do not disclose an unpatched vulnerability in a public issue.
Keep project trust and Ask permissions enabled unless unattended access is explicitly required. Download binaries only from the release channel controlled by the Sunsetz project.