Do not publish vulnerabilities, raw SMS, credentials, tokens, private keys, usable enrollment artifacts, or personal payment data in public issues, pull requests, logs, screenshots, or CI output.
A private security-reporting route is not yet published. Until maintainers publish and verify one, do not submit sensitive vulnerability details to this repository. Use a verified official maintainer channel outside the repository and share only the minimum information needed to establish contact.
Maintainers must publish the accountable security/release role, backup escalation path, acknowledgement target, disclosure coordination process, and emergency rebuild or revocation authority. They must also approve the vulnerability and dependency exception policy before automation can accept any exception.
Non-sensitive reports may describe affected version, high-level impact, reproduction using synthetic data, and whether a workaround exists. Do not include exploit payloads or operational topology details that make exploitation easier.