This is an internal, pre-release project. Report suspected vulnerabilities through the approved internal Plenora security channel. Do not disclose vulnerabilities in a public issue.
Reports should include the affected revision, a minimal reproduction, the expected impact, and whether secrets or production data may have been exposed. Never include live credentials or sensitive payloads in a report.
The current technical review, its exclusions, and release-approval checklist are documented in
docs/security-review.md. That document does not replace approval from
the designated Plenora security owner for an exact release commit.