Security fixes are applied to the active main branch and current milestone release line.
Please report vulnerabilities privately by opening a GitHub security advisory for this repository.
If security advisories are unavailable in your context, open a private report to the maintainers and include:
- affected file(s)/component(s)
- impact and exploitability
- minimal reproduction
- proposed remediation (if available)
Do not post sensitive exploit details in public issues before a fix is available.
- Initial acknowledgement target: within 3 business days
- Severity assessment: critical/high/medium/low
- Fixes are prioritized by exploitability and user impact
After remediation, publish a public summary including:
- affected versions/commits
- mitigation/fix
- any required user action
- Threat model (v0.7):
docs/security/THREAT_MODEL_v0.7.md - v0.7 design security section:
docs/milestones/v0.7/DESIGN_v0.7.md