Security fixes are provided for the latest 0.1.x public-alpha candidate or
published alpha only. Users should upgrade to the newest alpha patch before
reporting a vulnerability.
Do not disclose a suspected vulnerability in a public issue. Use GitHub's private vulnerability reporting feature. If it is unavailable, contact the repository owner through their public profile to request a private channel without including sensitive details in the initial message.
Include the affected version/commit, platform, impact, reproduction steps, and known mitigation. Remove sample identifiers, credentials, tokens, FASTQ/BAM, and confidential paths. Maintainers will assess and coordinate a fix and disclosure as capacity permits.
Scientific questions, routine run failures, documentation issues, and feature requests are not security reports. Commercial-license inquiries follow COMMERCIAL_LICENSE.md.