Security fixes are currently made on the latest revision of the main branch.
The project is pre-1.0, so downstream users should pin an exact revision and
review changes before deployment.
Please use the repository host's private security-advisory feature. Do not open a public issue for vulnerabilities, leaked credentials, or reports containing sensitive target-machine details. If private reporting is unavailable, contact a maintainer through an established private channel before sharing details.
Include the affected revision, impact, reproduction steps, and any proposed mitigation. Maintainers should acknowledge a complete report within seven days and coordinate disclosure after a fix is available.
Candidate and policy output is untrusted. It must not bypass the fixed-command compiler adapter, isolated correctness oracle, safety pipeline, benchmark promotion rules, content-addressed evidence store, or independent release qualification. Reports that cross this boundary, permit shell-command injection, mutate oracle truth, forge hardware origin, or weaken fail-closed stage ordering are considered security-sensitive.