- Do not commit probe credentials, signing material, serial captures containing personal data, or private media.
- Review any firmware image before flashing it to hardware.
- Keep generated release bundles tied to a reviewed source commit.
- Report suspected security issues privately through the maintainer's GitHub profile.