This is the organization-wide default security policy for Vaelii repositories.
A repository may override it with its own SECURITY.md, and the published ones
do — each describes the surface it actually has.
Please don't open public issues for security vulnerabilities.
Report privately through either channel:
- GitHub Security Advisories: use "Report a vulnerability" on the affected repository (preferred), or
- Email: support@vaelii.com with "SECURITY" in the subject line.
Include what you can: affected repository, version or commit, reproduction steps, and impact. Please practice coordinated disclosure — report privately first and allow time for a fix to land before publishing details.
main and the latest release are the only versions in scope. Older releases are
not patched.