Do not open a public issue for a suspected vulnerability. Use the repository host's private vulnerability-reporting feature. If private reporting is unavailable, contact the maintainers through an agreed private channel before sharing details.
Include:
- the affected component and revision
- minimal reproduction steps or a proof of concept
- expected impact and any known exploitation
- a suggested mitigation, if available
Do not include live credentials, access tokens, production personal data, or destructive test output. Allow maintainers time to reproduce and coordinate a fix before public disclosure.
This early-stage project supports only the current default branch. No security response timeline or production suitability is guaranteed.