The project is currently a development preview. Security fixes are accepted
for the latest main branch and latest tagged release.
Do not open public issues for vulnerabilities. Report them privately to the repository security contact configured by the project owner and include:
- affected version and deployment mode;
- reproduction steps;
- impact and required privileges;
- any known workaround.
Never include production credentials, customer data, or active exploit infrastructure. See docs/threat-model.md for the documented isolation boundary.