Please report security issues privately before opening a public issue.
- Include a clear description of impact and reproduction steps.
- Include affected commit hash or tag when possible.
- Include any proof-of-concept data needed to verify the issue.
I will acknowledge reports promptly and coordinate a fix and disclosure timeline.
Security reports are in scope for:
- memory safety issues
- integrity or correctness issues that can be exploited in deployed usage
- dependency vulnerabilities with practical impact