Report suspected vulnerabilities through GitHub private vulnerability reporting (repository Settings → Code security → Private vulnerability reporting). Do not open a public issue for a suspected vulnerability.
Target first response within 7 days.
Never include credentials, source code, diffs, transcripts, prompts, environment values, private project metadata, or customer data in a report. Provide the smallest synthetic reproduction possible.
The latest published release is supported. Security fixes may change
unsupported pre-release interfaces without notice; accepted public contracts
follow the compatibility rules in docs/protocol.md.
The mandatory threat and data boundaries are documented in
docs/security-privacy.md.