Please report security issues privately through the repository's security advisory form. Do not open a public issue for a vulnerability.
The preview is intended for controlled testing. Its helper executables are not yet platform-signed. The bundled catalog authorizes only reviewed, immutable third-party versions whose source hashes are committed with the manager.
The committed fixture signing keys make the bundled metadata reproducible but are not suitable for a network-updated public catalog. Remote catalog updates remain disabled until the documented signing ceremony is complete.
Supported public releases will be listed here once signing and platform certification are complete.