If you believe you have found a security issue in DecisionLayer, please do not open a public issue with exploit details.
Instead:
- report it privately to the maintainers once a security contact is established
- include clear reproduction steps
- include impact, affected files or packages, and suggested mitigations if known
Until a dedicated security contact exists, maintainers should set one up before the first public release.
Security reports are especially relevant for:
- local file parsing and bundle discovery
- CLI execution paths
- future IDE integrations
- future agent or hook integrations
- any code that reads untrusted repository content
Pre-1.0.0: best effort.