Please do not disclose security vulnerabilities publicly in issues or discussions.
Report security concerns privately to project maintainers through your preferred private channel and include:
- affected component/path,
- reproduction details,
- impact assessment,
- any known mitigations.
We aim to acknowledge reports promptly, validate impact, and coordinate a fix/release timeline.
High-priority areas include:
- authentication and credential handling,
- external control interfaces and network paths,
- secret management and deployment scripts.