Do not report vulnerabilities, credentials, customer records, or private client details in a public issue.
Use GitHub private vulnerability reporting when enabled for the affected repository. If unavailable, contact the repository owner privately through the verified organization account.
Security language must be tied to current implementation evidence. Terms such as secure, private by design, or compliance language are not certifications unless a current audit proves them.
A fix is complete only after the relevant validation and release evidence are recorded.