Report suspected vulnerabilities privately through the repository security advisory flow or by contacting the maintainers directly.
Do not open public issues for:
- Authorization bypasses.
- Over-cap settlement paths.
- Double-settlement paths.
- Asset or seller binding failures.
- Expiry bypasses.
- Replay or storage collision risks.
Public reports may be opened after a fix or mitigation is available.
The current contract control checklist for review is maintained in docs/security-checklist.md.