Report suspected vulnerabilities privately through this repository's GitHub security reporting channel when available. Do not include production document payloads, credentials or opaque compiled artifacts in public issues. If private reporting is unavailable, ask the maintainers for a private channel without disclosing exploit data.
The security contract explains the trust and resource boundaries. This package is a transport baseline and does not authorize documents or verify semantic release provenance.