There is no supported production release yet. Security fixes are made on the default branch during pre-release development.
Please use GitHub private vulnerability reporting for this repository. Do not open a public issue for a suspected vulnerability and do not include exploit details in public pull requests.
Include:
- affected commit/version and platform;
- impact and realistic attack path;
- minimal reproduction or failing test;
- suggested mitigation, if known;
- whether the issue has been disclosed elsewhere.
You should receive an acknowledgement within three business days and a status update within seven business days. Timelines for a fix and coordinated disclosure depend on severity and release impact.
The current audit backend does not enforce packets. Reports that rely on a claim of native blocking should first confirm that the repository version actually ships that backend. Local-console authentication bypass, revision/rollback failures, policy semantic downgrades, unsafe packet-data retention, and parser resource exhaustion are in scope.