Report suspected vulnerabilities privately to the contact listed in security.txt. Include the affected commit, reproduction steps and expected impact. Do not include credentials in public issues or PRs.
This repository contains research and development work; a successful CI run does not certify all language designs, proofs or deployment configurations.