The latest published ERSEC release is the primary supported version.
Please do not open a public issue for an undisclosed vulnerability. Use the repository's private GitHub security reporting mechanism when available, or contact the project maintainer through the private channel documented by the repository owner.
Security reports may include vulnerabilities in:
- scanner scope enforcement;
- request transport and evidence handling;
- Shield enforcement and policy compilation;
- credential redaction;
- generated contracts or release workflows;
- dependency/build/release integrity.
Do not include real secrets, production credentials, or private customer data in a report.