Security issues in source code, CI workflows, dependencies, and published artifacts are in scope.
- Do not open a public issue for a suspected vulnerability.
- Send details privately to the maintainer with:
- affected component and version/commit
- reproduction steps or proof-of-concept
- expected impact
- Initial acknowledgment: within 72 hours
- Triage decision: within 7 days
- Remediation plan (when confirmed): within 14 days
After a fix is available, coordinated disclosure is preferred.