Security reporting
Report suspected vulnerabilities safely.
Send a concise, reproducible report to the dedicated security channel. No bug-bounty, response-time, or resolution commitment is offered on this prelaunch page.
Before you send a report
- Describe the affected release, environment, impact, and minimal reproduction.
- Do not send credentials, secrets, personal data, repository contents, or production data unless specifically requested through an agreed secure channel.
- Do not disrupt systems, access other people's data, or exceed what is necessary to demonstrate the issue.
Review the trust boundary.
See what Verify checks, what it prevents, and what always remains a human responsibility.