During the local v0.1 milestone, only the current 0.1.x working tree is supported. There is no published package or hosted release.
Do not disclose vulnerabilities publicly or include secrets/reproduction traces in ordinary issues. Once the repository is hosted, use GitHub Private Vulnerability Reporting. Before then, retain the report privately and contact the maintainer through the approved private channel used to share this source. Acknowledgement, triage, and remediation timelines will be agreed privately because no public response channel exists yet.
Include affected version, impact, minimal inert reproduction, and suggested remediation. Never use production keys, sign transactions, submit transactions, or access systems you do not own.
Parser bypass, hash ambiguity, verifier-policy bypass, unsafe filesystem writes, fixture execution, secret leakage, and supply-chain compromise are security issues. Claims that a syntactically valid Solana reference is externally true are out of scope because v0.1 explicitly performs offline verification only.