Do not open a public issue for a suspected vulnerability, exposed credential,
or privacy incident. Report it privately to info@projectious.work with a
minimal reproduction, affected version, and impact. We will acknowledge the
report, coordinate remediation, and publish a disclosure when users need to
take action.
The current stable release line receives security fixes. Older releases may require an upgrade to receive a remediation.
This repository intentionally uses no GitHub Actions. Maintainers run the documented local checks before merging and releasing, and publish the commands and results with the change or release record.