The main branch receives security fixes.
Do not open a public issue for private intake exposure, credential leaks, release artifact contamination, or workflow security concerns.
Use GitHub private vulnerability reporting to send the repository maintainers a confidential report.
Use the TechSpokes contact route if GitHub private vulnerability reporting is unavailable.
Do not commit secrets, credentials, private customer material, or proprietary intake files.
Raw intake belongs in .intake/ during bootstrap and must not be included in release artifacts.