Report suspected vulnerabilities through GitHub private vulnerability reporting:
https://github.com/ApeCodeAI/apethon/security/advisories/new
Apethon assumes a trusted, author-controlled content repository. Raw HTML in Markdown and configured footer/CTA HTML is rendered intentionally. Do not use it for untrusted multi-tenant submissions without sanitization and isolation.
Keep credentials in deployment environment variables; never put tokens, private keys, or .env files in content or framework repositories.