The latest functional release accepts security reports for its documented persistence and registration behavior. Package-reservation releases that do not contain provider APIs are unsupported for application use.
Innovorium accepts good-faith reports about provider, repository, package, build, or release-security defects but makes no response-time, fix-time, backport, or compatibility commitment while the project is below 1.0.
Do not open a public issue or discussion. Use GitHub private vulnerability reporting.
Include the affected package and version (if applicable), impact, safe reproduction details, and any suggested mitigation. Never include production credentials, personal data, or active tokens. Maintainers will assess complete reports privately and coordinate disclosure after a fix is available.