Security fixes are applied to the current main branch and the latest published release.
Do not publish exploit details, credentials, tokens, private benchmark data, or other sensitive material in a public issue.
Prefer GitHub's private Report a vulnerability / Security Advisory flow when it is available for this repository. If that private channel is unavailable, open a minimal public issue that only requests a private contact path and does not include vulnerability details.
Relevant reports include vulnerabilities in repository automation, benchmark ingestion/validation, release workflows, or reference code that could cause untrusted contributed content to execute unexpectedly, alter releases, or expose secrets.
Reasoning-quality disagreements and ordinary protocol bugs are not security vulnerabilities; use the normal bug-report issue form for those.