XCMAX accepts vulnerability reports through GitHub private security advisories
or by email at security@xcagi.com. Do not disclose suspected vulnerabilities
in public issues.
The active supported product line is 1.0.x. Security fixes are released from
the root monorepo and identified by exact Git SHA and artifact digest.
The full reporting process, secrets policy, and contributor requirements are
maintained in FHD/SECURITY.md.