Shippy is currently beta software. Security fixes target the latest beta branch and release only.
Please report vulnerabilities privately through GitHub's security advisory form. Do not open a public issue for credential exposure, Crew authentication bypass, arbitrary media access, or remote-code-execution concerns.
Include affected versions, reproduction steps, impact, and a minimal proof of concept. Never include another person's credentials or private media.