Report suspected vulnerabilities privately through GitHub Security Advisories. Do not open a public issue.
Include the exact affected version, minimal reproduction, impact, topology, and sanitized evidence. Never include customer data, tokens, passwords, database dumps, certificate private keys, CA keys, signing keys, backup credentials, or raw telemetry.
The repository does not currently encode a fixed response SLA or supported-version matrix. Operators should deploy immutable versions and qualify security updates promptly.
See the full security reporting guide and deployment hardening.