Please do not report security vulnerabilities through public issues.
Use GitHub private vulnerability reporting for this repository when available. If private reporting is unavailable, contact the maintainers out of band and include a concise description, affected versions or commits, reproduction steps, and the expected impact.
We will acknowledge actionable reports as quickly as possible, coordinate a fix, and publish public details after users have had a reasonable opportunity to update.
Security reports for gitrdone should focus on authentication, authorization, repository isolation, token handling, Git transport behavior, Git LFS object handling, request logging, and persistence boundaries.