The latest tagged release is supported. Pre-release branches are not security support channels.
Do not open a public issue for an undisclosed vulnerability. Use the repository's private Report a vulnerability form under the Security tab. Include the affected version, smallest reproduction, impact, and any suggested mitigation. Remove device identifiers and secrets before sending evidence.
CableMancer reads local UTF-8 JSON, performs in-memory graph analysis, and writes requested reports. It does not execute configuration content, probe hardware, load plugins, or use the network. Input is capped at 1,000,000 bytes.
User labels are preserved in text and JSON reports. Markdown and Mermaid output escapes those labels for their target formats, but generated artifacts should still be reviewed before publishing if the input contains private information.
The analyzer is not a safety, electrical, certification, or real-device compatibility authority. Treating a static PASS as any of those claims is outside the security and product boundary.