Please do not open a public issue for a suspected security vulnerability. Use GitHub's private vulnerability reporting feature on this repository instead.
Include the affected SAM version, operating system, nftables version, a minimal
reproduction, and the security impact. Never include real production IP
addresses, credentials, or /etc/sam/rules.json contents unless they have been
sanitized.
SAM changes the host firewall and must run as root for mutating operations. Keep an independent recovery path, such as a hosting-provider console, when changing remote-access rules. Review release checksums before installation.