ReFineID handles card credentials and retry-limited operations. Please report security issues privately through GitHub's Report a vulnerability action on the repository Security tab. Do not open a public issue for a suspected secret leak, credential-handling flaw, card-lockout risk, or signature bypass.
Never include a real PIN, PUK, private key, personal identity code, certificate private material, or raw credential APDU in a report. Use structural descriptions and synthetic values. Maintainers can arrange a safer evidence transfer when needed.
The public tree is pre-release. No released version is currently designated as security-supported.