0.1.0-beta.1 is a beta. Security fixes apply to the newest beta only.
Do not open a public issue for an unpatched vulnerability. Use the repository
host's private security-advisory channel. Include the operating system, Git and
wip versions, the smallest reproduction, and whether a ref or source index
moved. Do not include tokens, private repository content, or full local paths.
The threat boundary is in THREAT-MODEL.md.