Do not open a public issue for an evaluator sandbox escape, fail-open result, resource-exhaustion vector, unsafe document behavior, dependency vulnerability, or sensitive data found in a fixture. Use GitHub's private vulnerability reporting / Security Advisory workflow for this repository.
Use only synthetic reproduction data. If private reporting is unavailable, contact an OpenNV organization owner privately and request a secure channel before sharing details.
Until the first stable release, fixes are applied to the latest main
revision. Consumers should pin an immutable commit or release tag together with
the compatible OutputFSM and runtime revisions.
Validation files are reviewed policy, not inherently trusted executable input. Consumers must strictly decode the documented schema, reject unknown fields and duplicate IDs, bound document and expression size, restrict expression inputs and syntax, enforce evaluation-step limits, and fail closed on missing or invalid evidence.
Never contribute production output, baselines, customer identifiers, credentials, routable management addresses, or proprietary policy material. Operational thresholds can disclose network design assumptions; keep private overlays in access-controlled repositories when needed.