Do not report a suspected vulnerability in a public issue.
Use the repository's private vulnerability reporting form:
https://github.com/d0lb33/WorkTrellis/security/advisories/new
WorkTrellis manages local development resources. It is not intended to hold production credentials, download production data, or expose container services outside the local host. Generated Compose ports bind to loopback.