Security fixes target the current main branch. Historical deployments and forks must be assessed by their operators.
Please use GitHub's private vulnerability reporting form under the repository's Security tab. Do not open a public issue for a suspected vulnerability or include participant data, credentials, wallet private keys, access tokens, or live service details in a report.
Include the affected commit, the trust boundary involved, reproduction steps using generated data, and the expected impact. Maintainers will acknowledge the report, validate it, and coordinate a fix and disclosure when appropriate.
The example configuration is not a production secret store. Operators must provide unique credentials, immutable image references, private database networking, backups, monitoring, and jurisdiction-appropriate privacy controls. Keep every optional real-data and reward capability disabled until its policy, consent, and operational gates have been reviewed.