No released version is currently supported. Security fixes target main until
the first project baseline is released.
Do not open public issues for vulnerabilities and do not include exploit details, payloads, or proof-of-concept code anywhere in public content.
GitHub private vulnerability reporting is enabled for this repository. Report vulnerabilities privately through the repository's Security → Report a vulnerability flow. A maintainer will triage the report and coordinate a fix and disclosure.
If you cannot use private reporting for any reason, contact a maintainer
through the invite-only Mattermost workspace (see COMMUNICATION).
Security work may include:
- Threat modeling
- Dependency and supply-chain review
- SBOM generation
- Secure CI/CD
- Secret scanning
- Vulnerability triage
- Incident response guidance
Security analysis in this repository is not a certification, homologation approval, or substitute for expert review.