Only the current main branch is reviewed for security fixes. Archived and
candidate artifacts may be retained for auditability but are not supported as
production releases.
Do not disclose suspected vulnerabilities, credentials, tokens, private data, or exploitable details in a public issue or pull request.
Use GitHub's private vulnerability reporting flow from the repository's Security tab. Include the affected path, impact, reproduction steps, and a suggested mitigation when available. The owner will assess the report and coordinate any public disclosure after a fix or containment decision.
This policy is a reporting channel, not a statement of production readiness or an open-source license.