Only the latest published release is supported while dotenvsec remains pre-production.
Do not open a public issue for suspected vulnerabilities or disclose secret material. Use GitHub private vulnerability reporting for philband/dotenvsec. Include the affected version, reproduction steps using synthetic secrets, impact, and any suggested mitigation.
Automatic shell loading requires an independent security review and the real-hardware verification described in docs/threat-model.md before production use.