Security fixes target the latest tagged release and the current main branch.
Older releases are not maintained unless a notice says otherwise.
Do not disclose a suspected vulnerability in a public issue. Use GitHub's private vulnerability report with reproduction steps, affected versions or revisions, likely impact, and any suggested mitigation.
Reports are acknowledged as maintainer availability permits. Response and resolution times depend on validated severity and are not guaranteed service levels. Coordinated disclosure and responsible research are welcome; do not access other people's data, degrade services, or test outside systems you own or are authorized to assess.
The supported contract is the maintained repository surface described in
AGENTS.md. Archived Conductor history, experiments/, third-party clients, and
downstream copies are outside the supported security boundary.