CGF is a documentation-led foundation with small reference implementations and demonstrations. It is not production-validated software, a medical device, or a certified robot-control system.
Use the public repository host's private vulnerability-reporting channel when available. Include the affected file, impact, reproduction steps, and a minimal proof of concept. Do not open a public issue containing credentials, private data, or an exploitable vulnerability before maintainers have had a reasonable opportunity to respond.
If private reporting is not enabled, ask for a private maintainer contact in a public issue without disclosing sensitive details.
Security fixes are considered for the current default branch. Research notes,
Labs fixtures, and applications retain the claim boundaries documented in their
own README and result files. A contract-pass result is not a security audit.