Please report security vulnerabilities through GitHub private vulnerability reporting for this repository.
Do not open a public issue for suspected vulnerabilities. Include the affected version or commit, reproduction steps, expected impact, and any relevant logs or proof-of-concept details.
Security reports are in scope for the CLI, npm installer, FFI boundary, release artifacts, GitHub Actions workflows, and platform adapters.
Maintainers will review private vulnerability reports, coordinate fixes, and publish security advisories when a vulnerability affects released versions.