Security fixes target the latest tagged release and the current main branch. Older revisions are not supported unless a maintainer explicitly identifies a backport.
Do not open a public issue for a suspected vulnerability. Report it privately through GitHub's private vulnerability reporting for this repository, or open a private security advisory.
Include, when relevant:
- the affected release or commit;
- the DeepSeek Harness snapshot and profile;
- the browser and operating-system versions;
- the impact and required preconditions;
- minimal reproduction steps or a controlled proof of concept;
- sanitized logs or screenshots needed to reproduce the issue.
Never send live API keys, authorization headers, complete prompts or conversations, or unrelated workspace files.
The maintainer will acknowledge the report as soon as practical, investigate it privately, and coordinate remediation and disclosure with the reporter.