Report vulnerabilities privately through GitHub's security advisory interface for this repository.
Published artifacts are built only from checksum-pinned upstream source archives. Consumers should verify both SHA256SUMS and the GitHub artifact attestation before packaging an executable.