| Version | Supported |
|---|---|
| 0.1.x | Yes |
| Earlier or unreleased snapshots | No |
Do not include sensitive details in a public issue. Use GitHub's private vulnerability-reporting form:
https://github.com/KanadeK/rectoready/security/advisories/new
Include the affected version, operating system, minimal reproduction, impact, and any safe mitigation you already found. You should receive an initial response within seven days. A confirmed issue will be coordinated privately until a fix and release note are ready.
RectoReady has no network or credential features. The highest-risk boundary is
untrusted manifest/CSV path input; reports should state whether the behavior
can read outside --capture-root, overwrite an existing output, or mutate a
source capture.