Security fixes target the latest code on the default branch and the latest published release when practical.
Please use GitHub's private vulnerability reporting for this repository. Do not include secrets, exploit details, or user data in a public issue.
Include the affected platform and version, reproduction steps, impact, and a minimal proof of concept if safe. Maintainers will acknowledge a complete report as soon as practical and coordinate disclosure after a fix is available.
Script execution, fetched content, imported .swt packages, iCloud documents, app-group storage, and AI-generated code are trust boundaries. Never commit API keys or personal data to a sample widget.