Please use GitHub's private vulnerability reporting for this repository. Do not publish an undisclosed vulnerability as an issue and do not include credentials, personal data, private source code, or unreleased holdout answers.
Include the affected commit, reproduction steps, the violated integrity or isolation invariant, and expected impact. Reports involving runner isolation, artifact integrity, answer leakage, provenance, or evaluator manipulation are especially relevant.
Secure Bench is pre-1.0. Security fixes target the latest release and main. Historical benchmark phases are immutable research records rather than maintained release lines.
Benchmark results are bounded synthetic measurements. They must not be represented as general security coverage, scanner superiority, or production readiness.