Do not open a public GitHub issue for security vulnerabilities.
Report privately using GitHub Private vulnerability reporting (Security Advisories):
- Open the repository Security tab.
- Choose Report a vulnerability, or go directly to Report a vulnerability.
Repository maintainers must enable Private vulnerability reporting under Settings → Security → Code security and analysis if the option is not visible.
Include: description, impact, reproduction steps, and affected components if known.
Threat model, invariants, and engineering controls are documented in:
We aim to acknowledge reports within 5 business days. Critical issues affecting tenant isolation or secrets will be prioritized.