Report suspected vulnerabilities through GitHub private vulnerability
reporting for rootform-dev/rootform. Do not open a public issue for an
exploitable finding.
Never attach real Terraform state, plans, credentials, account identifiers, or customer infrastructure. Reproduce with synthetic examples.