Do not open a public issue for a vulnerability.
Report privately through GitHub Security Advisories.
Include bran --version, the command you ran, and the JSON it printed. Redact
repository paths and source excerpts you would not publish.
For conduct reports, use the same private advisory form and state that it is a code of conduct report. See CODE_OF_CONDUCT.md.