Security and safety fixes are applied to the latest tagged release and the default branch.
Use GitHub private vulnerability reporting for credentials, dependency issues, unsafe release artifacts, or concerns that require non-public context. Do not include operational biological details in a public issue.
Use a public issue for ordinary data-quality, documentation, or reproducibility problems when the report can be written without sensitive details.