Report vulnerabilities privately through the repository's GitHub security advisory page. Do not open a public issue for an undisclosed vulnerability.
The Vercel build planner controls where Convex deployment credentials may be used. Treat changes to target classification, deploy-key parsing, deployment-name matching, environment scrubbing, subprocess arguments, and refusal behavior as security-sensitive.
Security fixes are supported on the latest release. Include affected versions, synthetic reproduction conditions, and impact in a report. Do not include live credentials, deployment names, or private provider data.