Security fixes are prioritized for the latest tagged release and the current main branch.
Do not open a public issue for a security vulnerability.
Please report suspected security problems privately to the repository maintainer through the GitHub security contact mechanism or another private channel you already have.
Include:
- What component is affected
- How to reproduce the issue
- Any logs, manifests, or versions involved
Release artifacts may include:
- OCI image labels
- SBOM output
- Provenance attestations
- Image signatures
These are meant to help end users verify and audit releases.