Use GitHub private vulnerability reporting. Include the affected version, smallest reproduction, impact, and which protection fails. Use systems you own or are authorized to test.
Do not disclose private data or credentials. Avoid public exploit reports until maintainers have investigated the report and coordinated a correction.
The latest 0.1.x release receives fixes. Stage is an early project with no guaranteed response time. Applications remain responsible for authentication, resource authorization, deployment, backups, and dependency updates.