Security fixes target the latest released version and the default branch.
Please use GitHub private vulnerability reporting for this repository. Do not open a public issue containing exploit details, credentials, private paths, chat data, contact information, or Vault contents.
Include only the minimum synthetic reproduction needed to understand the problem. Maintainers will acknowledge the report, assess impact, and coordinate disclosure and remediation.
TROVE is local-private software, but local operation does not make committed data safe. Keep every real Vault, source archive, media file, transcript, provider payload, log, and credential outside Git.