# Security policy This project is not public yet and does not have a public vulnerability intake address. Do not publish vulnerability details in an issue or commit. Report urgent findings to the project owner through the private project channel and include the affected commit, image tag/digest, reproduction steps, and whether state or output data is exposed. The public contact, response SLA, supported release branches, and disclosure process will be added after ownership and license approval. Container images must never contain credentials, production state, private registry settings, or internal hostnames.