Do not disclose a suspected vulnerability in a public issue or discussion.
Use GitHub private vulnerability reporting. Include the affected version or commit, impact, prerequisites, reproduction steps, and any suggested mitigation. Do not include live credentials, private keys, or data belonging to another party, and do not send security reports to the project's general contact or sponsorship addresses.
The project will acknowledge a credible report as maintainer capacity permits, coordinate validation and remediation privately, and publish appropriate credit unless the reporter prefers otherwise. No fixed response or disclosure deadline is promised during MVP.
AcmeMux is pre-release software. Only the platforms and exact lego artifacts named in public documentation are qualified. Security reports about unsupported deployments are welcome evidence but may require reproduction on a qualified environment.