Please do not report security vulnerabilities through public GitHub issues.
If GitHub private vulnerability reporting is enabled for this repository, use the repository's Security tab to open a private report. If that option is not available, contact the maintainer through the public contact method listed on the Cubits11 GitHub profile and include:
- the affected commit, release, or package version;
- a minimal reproduction or proof of concept;
- expected impact and affected workflows;
- whether the vulnerability is already public.
You should receive an initial acknowledgement within 7 days. The maintainer will coordinate next steps, remediation, and disclosure timing based on impact.
Security reports are appropriate for vulnerabilities in repository code, release artifacts, example workflows, or integrity/audit evidence handling.
Methodology questions, statistical disagreements, documentation issues, and general feature requests should use the normal issue templates instead.
Private vulnerability reporting could not be verified or enabled from the 2026-07-01 Codex hardening session because the local environment did not have an authenticated GitHub CLI or token. A repository admin should verify this in GitHub settings before launch.