The authoritative security policy is maintained in the repository root:
Please use that policy for:
- Supported versions
- Private vulnerability reporting
- Shell injection, profile writing, registry edit, PATH hijacking, and unsafe environment mutation concerns
If you discover a security issue in the documentation site infrastructure, build pipeline, or published assets, use the same private disclosure channel and clearly state that the issue concerns documentation delivery.