Project
Security
Report vulnerabilities privately and understand the project's security boundary.
Do not report security issues in a public issue. Use GitHub private security advisories so a fix can be prepared before disclosure. The latest minor release receives security fixes.
For the complete reporting policy, see SECURITY.md.
Every pull request must pass the dependency-review and repository-policy checks before it can merge. The repository-policy check treats changes from external forks as untrusted and rejects edits to the repository control plane.
