1.0.x: security and reliability fixes only.0.x: best-effort, no guaranteed SLA.
- Email maintainers with reproduction steps, impact, and affected versions.
- Do not open public issues for unpatched critical vulnerabilities.
- We acknowledge within 3 business days and provide a remediation timeline.
- Default disclosure window: 90 days.
- Critical infrastructure-impact issues may be disclosed sooner after patch publication.
pnpm security:auditpnpm security:fuzzpnpm sbom:generate
External audit and long burn-in validation are tracked separately from in-repo gates.