Do not disclose vulnerabilities or sensitive evidence in a public issue or PR. If private vulnerability reporting is available in this repository's Security tab, use it. Otherwise, open a private contact request asking the owner for a private route. That request is public: include no vulnerability details, credentials, or personal data.
A useful private report includes the affected commit or version, impact, and a minimal reproduction. Use synthetic data and redact credentials, personal conversations, memory/persona data, user files, and operational logs.
LINA has no released versions yet. Supported versions, update paths, and reporting procedures will be defined before the first release; no response-time commitment is currently offered.
Review files and evidence before publishing them. Do not commit secrets, personal data, local installation details, or operational state; .gitignore is not a substitute for that review. Changes to permissions, authentication, or data access need an explicit explanation of their impact.
The CI policy defines isolation and execution requirements for external contributions.