Do not disclose a suspected vulnerability in a public issue. Use the affected
repository's Security tab and open a private vulnerability report. If the
repository cannot be identified, start with
atrinik/atrinik.
Include affected versions or revisions, impact, reproduction details, and any known mitigation. Maintainers will coordinate validation, remediation, and disclosure through the private advisory.
Only supported default and explicitly maintained branches receive security fixes. Archived repositories are retained for history and are not supported.