Report vulnerabilities privately through the Kalcite Engine security advisory page.
Do not open a public issue for a vulnerability that could affect projects using a published package. Include affected package names, commit IDs, a minimal reproduction, and any practical mitigation.