Do not open a public issue, discussion, pull request, or social-media post for a suspected vulnerability. Use GitHub's private vulnerability reporting for the affected repository when it is available. If that channel is unavailable, contact an organization owner through a private, previously verified channel and request a secure reporting route; do not include exploit details or secrets in the initial message.
Include the affected repository and commit/version, environment, impact, prerequisites, minimal reproduction, and any suggested mitigation. Remove personal data, live credentials, private keys, and unrelated customer information.
We will acknowledge a usable report when maintainers are available, establish a private coordination channel, assess scope, and communicate a remediation/disclosure plan. Because these products are pre-release, this policy does not promise a paid bounty, a fixed response time, or production support SLA.
Only the current default-branch baseline and releases explicitly marked as supported are eligible for security fixes. At present, no public production release is declared supported. Development snapshots and unapproved forks may change without compatibility guarantees.
Please allow maintainers a reasonable opportunity to validate and remediate before public disclosure. Do not access data beyond what is necessary to demonstrate the issue, degrade services, persist access, or test against systems you do not own or have permission to assess.
If credentials or signing material may have been exposed, report that fact without pasting the value. Maintainers will rotate or revoke affected material and preserve an auditable incident record.