Report vulnerabilities through GitHub's private vulnerability reporting for this repository. Do not open public issues for unpatched vulnerabilities.
Runtime boundaries are security-sensitive. Reports involving guest memory access, hostcall bounds, path traversal, asset limits, GPU wire validation, compiler/interpreter parity, or worker lifecycle cleanup should include the affected source revision and backend.