This repository contains CPU-only educational code and does not operate a hosted service. Still, report a suspected vulnerability without including exploit code, credentials, or sensitive data in a public issue.
After the repository is published, use its private vulnerability-reporting channel when available. If that channel is unavailable, open a minimal issue requesting a non-public contact path and include only the affected version, impact category, and reproduction prerequisites.
Maintainers aim to acknowledge a report within seven calendar days. Fix timelines depend on severity, reproducibility, and whether the issue affects distributed package artifacts.