Please do not open a public issue for a suspected security vulnerability.
Keep secrets, connector credentials, access tokens, private customer data, member identifiers, and environment-specific account IDs out of this repository. The checked-in pod is designed to be bound to those resources after import.
When reporting a vulnerability, include the affected resource, the trust boundary crossed, and a minimal reproduction that does not contain real credentials or private data.