This is the organization-wide default. A repository with its own SECURITY.md
overrides it. Wizzy, Lyre, and Brush each have one, and theirs is authoritative for those
projects.
Do not open a public issue for a vulnerability.
- Public repositories: use GitHub's private vulnerability reporting on the repository (Security, then Report a vulnerability).
- Private repositories: report through the private channel by which your access was granted.
The affected commit or toolchain, the platform, the observed behavior, the security boundary you expected to hold, and the smallest evidence needed to explain the concern.
Remove credentials, private source, and personal data before sending.
This software is early. Most of it is private, none of it has a published release, and this organization has not established supported versions, a disclosure timeline, a response-time commitment, or an acknowledgement process. Those become real per project at that project's own public-preview gate, and are recorded there. A report will be read and handled.