Report suspected vulnerabilities through GitHub private vulnerability reporting. Do not publish exploit details, credentials, live endpoints, captures, or an unfixed vulnerability in a public issue or discussion.
Include the affected commit, configuration boundary, reproduction steps, impact, and whether the behavior also exists in the unmodified upstream baseline. Reports are triaged for the fork first. Confirmed issues inherited from upstream may then be coordinated privately with the upstream maintainers.
Only the current main branch is reviewed. The repository is experimental and
does not currently publish supported binaries or production releases.