Please report suspected vulnerabilities privately using Report a vulnerability. Do not put credentials, exploitable details or private installation data in a public issue. You need a GitHub account to submit a private report.
Include the affected source revision or artifact, prerequisites, a minimal reproduction and expected impact. Use synthetic data and redact logs. Do not test against other users, production installations or services without permission.
This is a design-stage project with no supported OS image release yet. Report source and proposed trust-boundary issues; documentation does not establish that host privilege, independent desktops or recovery are implemented securely. Product-runtime issues belong in the Lina project's security channel.
The maintainer will assess reports as capacity permits; no response-time or bug-bounty commitment is made.