This alpha processes caller-controlled JSON under fixed limits, but it is not a security boundary. Conflict responses can reproduce sensitive input values.
Do not open a public issue for a suspected vulnerability or include live
secrets in a report. Send a minimal reproduction to
antunjurkovic@gmail.com with the subject libdualnative security report.
Encrypt or redact sensitive fixtures before sending them.
The maintainer will acknowledge a report when available, reproduce it against the exact engine identity, and publish a versioned correction or advisory when warranted. No response-time SLA is promised for this experimental alpha.
Supported security maintenance is limited to the latest GitHub public alpha,
currently v0.1.0-alpha.1. Development snapshots and internal source
checkpoints are not separately supported releases. The package is not
published to crates.io or npm.