Do not open a public issue. Send a private report through GitHub's Security → Report a vulnerability form. Include the affected version, impact, reproduction steps, and a minimal proof of concept. Do not access data that is not yours or disrupt a deployed environment.
We acknowledge reports within three business days, provide a triage update within seven business days, and coordinate disclosure after a fix is available. Good-faith research that follows this policy will not be pursued legally.
The latest commit on main and latest tagged release receive security fixes.
Older deployments must upgrade before requesting a patch.
Operational guidance is in docs/SECURITY.md, docs/THREAT_MODEL.md, and
docs/PENTEST_CHECKLIST.md.