Celestial is in public preview. Security fixes are supported for the latest published preview versions of @celestial/core, its six implementation packages, @celestial/ui, @celestial/test, and the latest Horizon beta.
Do not open a public issue for a suspected vulnerability or exposed credential. Use GitHub's private vulnerability reporting for this repository and include:
- the affected package and version;
- a minimal reproduction;
- expected impact;
- any known mitigation.
You should receive an acknowledgement within seven days. Preview APIs may change as part of a security fix.
Code outside this focused repository is not covered by this policy.