Security fixes target the current default branch and the latest published release. Older releases may be evaluated case by case, but are not guaranteed to receive fixes.
Do not open a public issue or discussion for a suspected vulnerability.
If GitHub shows a Report a vulnerability button on the repository Security
page, use it to submit a private report. Otherwise, email
fallintodusk@proton.me with the subject [ALIS SECURITY].
Include the affected release or commit, the expected impact, reproduction steps, and any safe supporting evidence. Do not send credentials, private keys, or unrelated personal data.
ALIS aims to acknowledge a report within seven days. Validation, remediation, and coordinated disclosure timing depend on the issue's scope and impact.