object-log is pre-release software. No released version currently receives a
formal security-support period.
Please do not disclose a suspected vulnerability in a public issue. Use GitHub private vulnerability reporting to share the affected revision, reproduction steps, impact, and any suggested fix. Non-sensitive correctness and reliability reports belong in the public issue tracker.
Never include live credentials, recovery tokens, private repository contents, or production object-store paths in a report.