Report reproducible bugs through the GitHub issue tracker. Use the bug report form and include the CLI version, operating system, command, expected behavior, actual behavior, and minimal reproduction steps.
Before submitting logs or configuration, remove API tokens, authorization
headers, profile IDs, account IDs, transfer IDs, and other financial or personal
data. Never attach .env.local or paste an active Wise API token into an issue.
Do not disclose a security vulnerability, exposed credential, or exploit in a public GitHub issue. Report it privately through GitHub Security Advisories.
Include a clear description, affected version or commit, reproduction steps, impact, and any suggested remediation. Please allow the maintainers a reasonable opportunity to investigate and release a fix before public disclosure.
If a Wise credential has been exposed, revoke it immediately in Wise, replace it anywhere it is used, and remove it from affected files and Git history.
Security fixes target the latest release and the current main branch. Older
versions may not receive security updates.