Please use GitHub's private vulnerability reporting for this repository. Do not open a public issue for an undisclosed vulnerability and do not include credentials, personal data, or third-party source code in a report.
Include the affected version or commit, the broken security invariant, reproduction steps, expected impact, and any suggested mitigation. We will acknowledge the report, validate it against the supported scope, and coordinate disclosure when appropriate.
Secure Engine is pre-1.0. Security fixes are applied to the latest release and main; older development phases are retained for research reproducibility but are not maintained release lines.
Secure Engine is a static analysis aid, not a security guarantee. Findings require human validation. A clean scan does not establish that a project is secure or production-ready.