Security fixes are applied to the latest released Lifecycle.NET version. Prerelease builds may change rapidly and should not be used as the only control for production security.
Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting feature for this repository when it is enabled. If it is unavailable, contact the maintainers through the repository owner’s published security channel with:
- a clear impact description;
- affected package and version;
- reproduction steps or a minimal proof of concept;
- any suggested mitigation.
Do not include secrets, access tokens, or private customer data. We will acknowledge a report, assess severity, and coordinate disclosure before publishing details.