Please report security issues privately to the repository maintainers (see .github/CODEOWNERS).
- Prefer a private channel (maintainer email / GitHub Security Advisory / private message) over a public issue.
- Do not open a public GitHub issue that dumps exploit details, proof-of-concept payloads, or CVE write-ups before maintainers have had a chance to respond.
- Include enough detail for maintainers to reproduce and assess impact (affected version/commit, environment, steps).
We will acknowledge reports and coordinate disclosure after a fix or mitigation is available.
Security fixes are applied on a best-effort basis to the default branch (main) and recent releases as maintainers decide. Always prefer the latest published images/chart when deploying.