Security fixes are provided for the latest released version of OpenCode Nexus.
Please do not disclose suspected vulnerabilities publicly before they have been reviewed.
Use GitHub private vulnerability reporting for this repository when it is available. If private reporting is unavailable, contact the maintainer through GitHub without publishing exploit details, credentials, or other sensitive information.
Please include:
- the affected Nexus version or commit;
- reproduction steps;
- expected and observed behavior;
- the potential security impact; and
- any suggested mitigation, if known.
Reports will be reviewed and remediation and disclosure will be coordinated as appropriate.