Please report security issues privately by emailing security@qase.io.
Do not open a public GitHub issue for vulnerabilities or credential leaks. Include enough detail to reproduce the issue, the affected version or commit, and any relevant logs with secrets removed.