The repository is a normative draft and has no supported release. Security-sensitive issues can affect CI, dependency pinning, GitHub configuration, architecture artifacts, or the integrity of generated formal-model evidence.
Report such issues privately with a GitHub security advisory. Do not open a public issue for a suspected credential leak, supply-chain compromise, or exploitable CI behavior.
Include affected commits, reproduction steps, impact, and any proposed mitigation. Maintainers will acknowledge the report, assess exposure, and coordinate disclosure through the advisory.