Do not open a public issue for suspected vulnerabilities. Use GitHub's private vulnerability reporting for this repository when available, or contact the repository owner privately through their GitHub profile.
Include affected versions or commits, impact, reproduction details, and any suggested mitigation. Do not include live credentials, private repositories, customer source, or destructive proof-of-concept data.
Weft is pre-release and has no supported production version. Security-sensitive design changes still require denial-path, secret-redaction, permission-boundary, and recovery evidence.
Weft coordination metadata is not an authorization bypass. Provider operations must respect repository permissions, branch protection, review policy, and provider authentication.