Skip to content

Security policy

The full security policy (supported versions, reporting process, trust boundaries) lives at the repository root:

SECURITY.md

Report a vulnerability

Do not put vulnerability details in a public issue.

  • GitHub private vulnerability reporting is not currently enabled for this repository, and no public security email is published.
  • Until a confidential channel exists, open a public issue without vulnerability details and ask the maintainer to establish a private channel before sending the report.

Human trust overview: Trust & Safety