Do not open a public issue for a vulnerability that could expose recovery keys or permit alias forgery.Use GitHub's private vulnerability reporting feature for this repository.
Never include a real recovery key,forwarding address,or private email content in a report.Use a newly generated test key and synthetic addresses when a reproduction requires them.
For the protection scope and limitations,see the security model.