P3 stores bearer credentials for T3 Code in PebbleKit JS settings and sends them only to the base URLs configured by the user. Please do not include real tokens, private tailnet hostnames, or production data in public issues.
Use GitHub's private vulnerability reporting for
breakthebeta/p3code.
Include the affected version, impact, reproduction steps, and any suggested
mitigation. Please allow time for a fix before public disclosure.
General bugs that do not expose credentials or private data can use the public issue tracker.