If you discover a security issue in tooling, automation, or repository configuration:
- Do not open a public issue with exploit details.
- Contact the maintainer privately.
- Provide reproduction steps, impact, and suggested mitigation.
- Initial acknowledgment: within 7 days.
- Status update after triage.
- Public disclosure after fix coordination.