Please do not open a public issue for security problems.
Use GitHub private vulnerability reporting: https://github.com/do-now-io/socle/security/advisories/new
We acknowledge reports within 5 business days. While the project is pre-1.0 we do not commit to a fix SLA; confirmed vulnerabilities are prioritized ahead of all other work and shipped through the hotfix release path.
Pre-1.0: only the latest minor release receives security fixes.