Security fixes target the latest published release.
Report vulnerabilities privately through support@xquik.com.
Do not open public issues for secrets, credential handling defects, private data exposure, or package supply-chain concerns.
We aim to acknowledge reports within 3 business days. We will coordinate a disclosure timeline after confirming the issue.
Security-sensitive areas include API key handling, request construction, response parsing, package metadata, dependencies, and release workflows.