Please report vulnerabilities privately and do not disclose them publicly before a fix is available.
When reporting, include:
- Affected version/commit
- Reproduction steps
- Impact assessment
- Suggested mitigation (if available)
- Acknowledge report receipt
- Reproduce and triage severity
- Implement and validate fix
- Coordinate disclosure timeline
This policy covers the GRIT Engine source code and distributed package artifacts.