Email aadil@pushary.com to report a vulnerability privately. Include the affected repository and version, steps to reproduce, and the expected impact. Do not open a public issue or include API keys, account tokens, or customer data.
For agent plugins, report instructions that expose secrets, unsafe configuration, or approval behavior that continues without permission. Hosted Pushary account and connector vulnerabilities can use the same address.
We will coordinate disclosure, any necessary mitigation, and credit with the reporter. Fixes are published in a new release. Do not publish an exploit before discussing it with the maintainer.