Security fixes are made against the latest main branch. Older verifier snapshots and tags are not maintained release lines.
Use GitHub private vulnerability reporting through the repository's Security tab when available. Otherwise email contact@jadenrazo.dev with the affected commit or path, impact, and a minimal reproduction.
Do not open a public issue containing credentials, private release locations, unpublished artifact metadata, or a working verification bypass.
Checkout avoidance, immutable dependency pins, artifact provenance, digest or signature verification, and GitHub Actions trust boundaries are in scope. Vulnerabilities in third-party verification tools should also be reported to the relevant upstream project.