Use GitHub's private vulnerability reporting / Security Advisories for this repository when available. Do not open a public issue for security-sensitive reports.
If private vulnerability reporting is unavailable, open a minimal public issue without exploit details and state that you can share additional information privately with maintainers.
This repository is pre-release and contains specifications, vectors, documentation, and research-stage reference implementations. Report any issues that impact the confidentiality, integrity, or availability of those artifacts.