This page has moved. The canonical vulnerability-reporting policy — supported versions, how to report, vulnerability classes, severity, and response timelines — now lives in the repository root
SECURITY.md.
For broader security practices (integrator guidance, node-operator hardening, package provenance verification, audit information, and incident response), see the Security Guide.
For the protocol-level attack surface analysis, see the Threat Model.
This stub is kept so existing links to docs/security.md continue to resolve.