Only the current main branch is supported for security fixes. Historical
commits, forks, and archived artifacts may not receive updates.
Do not disclose a suspected vulnerability in a public issue, discussion, or pull request.
Use this repository's private vulnerability-reporting channel in GitHub's Security tab. Include a minimal reproduction, affected revision, expected and observed behavior, and impact. Do not include credentials, access tokens, private source material, private prompts, transcripts, or personal data.
If private reporting is not available, open a public issue containing only a request for a secure reporting channel. Do not include vulnerability details.
Reports are assessed on a best-effort basis. This project does not offer a service-level response-time commitment.
Security reports concern unintended access, modification, execution, availability loss, or disclosure caused by this repository or its deployment configuration. Research disagreement, terminology disputes, and unverified claims belong in the project's ordinary review process, not security reports.
Do not test by accessing accounts or data without authorization, disrupting services, or publishing private material.