Report security vulnerabilities privately. Do not open public issues for suspected vulnerabilities.
Document supported release branches or versions here.
| Version | Supported |
|---|---|
| main | Yes |
Include:
- Affected component or endpoint.
- Reproduction steps.
- Impact.
- Evidence, redacted where needed.
- Suggested remediation if known.
Security-sensitive code changes should follow SECURITY_REVIEW.md.
Penetration testing requires explicit authorization and scope. Use
PENTEST_SCOPE_TEMPLATE.md before testing.