README.md already states the supported imports and the planned deprecation timeline (0.4 silent → 0.6 warn → 1.0 enforce). This issue tracks the work to make the policy testable:
- A test that imports every documented public name and fails the build when a new name leaks in unintentionally.
- A
SECURITY.md covering how to report vulnerabilities.
- A short
docs/stability.md that mirrors the README table.
README.mdalready states the supported imports and the planned deprecation timeline (0.4 silent → 0.6 warn → 1.0 enforce). This issue tracks the work to make the policy testable:SECURITY.mdcovering how to report vulnerabilities.docs/stability.mdthat mirrors the README table.