Do not report vulnerabilities in public issues. Use GitHub private vulnerability reporting when available or contact community@iicp.network.
Never submit credentials, production database contents, operator records, private endpoints, or task payloads. The directory is a control plane and must not receive or log task payloads.
Supported security fixes target the current main branch until a formal release support policy is published.