- Core - Community Edition (this repository): best-effort security fixes.
- Commercial Data Center packaging and private safety modules: handled under commercial support channels.
Do not open public issues for suspected vulnerabilities.
Report privately with:
- summary and impact
- affected files/components
- reproduction steps
- logs/screenshots if available
Preferred contact:
If no response within 7 days, resend with [SECURITY][FOLLOW-UP] in the subject.
- We prefer coordinated disclosure.
- Please allow reasonable remediation time before public disclosure.