Security and data-integrity fixes currently target the latest commit on
main and the latest published release when releases begin.
Use GitHub's private vulnerability reporting feature for issues that could corrupt save data, expose private evidence, bypass collision protection, or violate the semantic-generation/physical-image isolation boundary. Do not attach private saves, ROMs, credentials, or proof packages to a public issue.
For ordinary reproducible bugs, use the public bug form with synthetic or public data only.