Project

Security

Report vulnerabilities privately and understand the project's security boundary.

Do not report security issues in a public issue. Use GitHub private security advisories so a fix can be prepared before disclosure. The latest minor release receives security fixes.

For the complete reporting policy, see SECURITY.md.

Every pull request must pass the dependency-review and repository-policy checks before it can merge. The repository-policy check treats changes from external forks as untrusted and rejects edits to the repository control plane.