SECURITY
Report privately. Reproduce minimally.
Security-sensitive surfaces include parsing, source discovery, repair, migration, publication locks, manifests, receipts, LSP process execution, and generated artifacts.
DISCLOSURE
Do not open a public issue.
Use GitHub private vulnerability reporting or email hello@pliegocss.dev with the affected version, minimal reproduction, impact, prerequisites, and mitigation.
hello@pliegocss.dev ↗SUPPORTED
Latest candidate + main
Before 1.0, fixes target the latest prerelease and the default branch. Response goals are not an SLA.