Until the first stable release, security fixes target the latest tagged release and the main branch.
Use GitHub's private vulnerability reporting for this repository when available. Do not publish secrets, personal data, private project material, or working exploit details in a public issue.
Include:
- the affected file or workflow;
- impact and realistic attack path;
- minimal reproduction steps;
- suggested mitigation, if known.
Use the private report to coordinate timing and disclosure with the maintainers. Public disclosure should wait until a fix or mitigation is available.
ConceptOps is instruction-only and ships no runtime service. Reports are still welcome for prompt-driven data exposure, unsafe external actions, path handling, misleading authorization boundaries, or bundled content that could disclose sensitive information.