Security fixes target the current main branch and the current public Rule1 release. Older retained framework data is part of the catalogue history, not a supported application version.
Use GitHub's private Report a vulnerability form in this repository's Security tab when it is available. If it is unavailable, open a public issue asking the maintainers to establish a private reporting channel, but do not include exploit details, secrets, personal information, or sensitive data in that issue.
Include the affected route or component, reproduction conditions, likely impact, and any safe proof of concept. Reports concerning the browser application, ingestion pipeline, build workflow, dependency supply chain, or catalogue-integrity checks are in scope. Corrections to publisher framework content should instead identify the authoritative source and affected version.
There is no bug-bounty programme or guaranteed response time. Please allow maintainers a reasonable opportunity to investigate before public disclosure.