This repository is currently in active Phase 0.5 development. The main branch is the supported branch for security fixes.
- Do not open a public issue for suspected vulnerabilities.
- Use GitHub's private vulnerability reporting for this repository: Security Advisories.
- Include clear reproduction steps, impact, affected paths, and any proof-of-concept artifacts.
- Initial acknowledgement: within 2 business days.
- Triage and severity classification: within 5 business days.
- Remediation or mitigation plan: as soon as triage is complete.
- We follow coordinated disclosure.
- Public disclosure happens only after a fix or acceptable mitigation is available.
- Security regressions can block releases.
- Provenance and policy bypasses are considered high severity.
- Receipt or audit-chain tampering is considered high severity.
- Secret material exposure outside approved boundaries is considered high severity.