Do not open public issues for suspected vulnerabilities. Use GitHub private vulnerability reporting for raythings/rayact and include the affected version, platform, reproduction, and impact.
We acknowledge reports within two business days, triage within five, and target critical fixes within seven days. Release artifacts are retained; rollback changes npm dist-tags and the GitHub latest release rather than unpublishing evidence.