subswapper handles OAuth credentials for every account it manages. If you
find a vulnerability — anything that could leak, corrupt, or exfiltrate stored
credentials, escape the backup directory, or weaken file permissions — please
report it privately.
Use GitHub private vulnerability reporting to submit a report. Please include reproduction steps and the impact you see.
Please do not open a public issue for security problems, and never post credential file contents or tokens anywhere, including in private reports — redacted structure is enough.
You should get an initial response within a week. Fixes are released as soon as they are ready; there is no embargo process beyond that for a project of this size.