There is no supported release or production security guarantee yet. This repository contains source patches and build tooling only; generated binaries are not distributed.
Security reports are accepted on a best-effort basis for the current repository content: its source-acquisition logic, patch application, build tooling, verification scripts and publication gates. There are no supported versions or released binaries, and no response or remediation deadline is promised.
Do not put credentials, personal information or non-public vulnerability details in a public issue, discussion or pull request. Use GitHub's private vulnerability reporting for this repository: on its Advisories page, select Report a vulnerability. Include the affected revision, impact, reproduction steps and any suggested mitigation.
At public launch, first change the repository visibility to public, then immediately enable private vulnerability reporting, configure its notifications and verify the Report a vulnerability button before the launch is announced or considered complete.
If the repository is public but the Report a vulnerability button is unavailable, open a public issue containing no vulnerability details and state only that the confidential reporting channel is unavailable.
For a problem in unmodified Recoil or a fetched third-party component, follow that project's current security policy or coordinated-disclosure instructions instead of assuming that this repository owns the response.