Please do not open a public issue for a suspected vulnerability or credential exposure. Use GitHub's private vulnerability reporting feature on this repository instead.
Include the affected command, impact, reproduction steps, and any suggested mitigation. Remove tokens, personal data, and private repository details from your report.
Security fixes target the latest released version. Users should update before reporting an issue that may already be resolved.
GitPilot stores credentials outside project repositories and masks known token formats in output. Even so, review staged files before every push and immediately revoke any credential that may have been exposed.