Declared Coherence does not read repositories, execute artifact content, access networks, or mutate caller data. Security reports should nevertheless describe the affected version, a minimal reproduction, and the impact at the programmatic API boundary.
Use the repository host's private vulnerability-reporting mechanism when it is available. Do not publish sensitive exploit details, secrets, or affected repository data in a public issue.
If the repository host does not provide a private reporting mechanism, use a non-public contact method published by a maintainer. This document does not assert that any host feature is already enabled and does not promise a response-time service level.