Security Policy
Supported Versions
This is an active codebase; security fixes follow best‑effort policy until a formal versioning scheme is adopted.
Reporting a Vulnerability
Please email the maintainers privately. Provide a minimal reproducible case and impact assessment. Avoid opening public issues for undisclosed vulnerabilities.
Secrets Handling
Do not commit real keys.
Prefer environment injection in CI/CD.
Rotate tokens regularly.