Security Policy

Supported Versions

This is an active codebase; security fixes follow best‑effort policy until a formal versioning scheme is adopted.

Reporting a Vulnerability

Please email the maintainers privately. Provide a minimal reproducible case and impact assessment. Avoid opening public issues for undisclosed vulnerabilities.

Secrets Handling

  • Do not commit real keys.

  • Prefer environment injection in CI/CD.

  • Rotate tokens regularly.