# Security policy

Please report vulnerabilities privately through GitHub Security Advisories for this repository. Do not include access tokens, refresh tokens, OAuth authorization codes, Client IDs tied to a private deployment, or callback URLs containing query parameters in public issues.

Credentials stay on the local machine under `~/.dsh/x-connect/`. If a credential may have leaked, revoke the app session in X, disconnect the plugin, and authorize again.
