Security fixes are applied to the latest release and the main branch.
Do not disclose suspected vulnerabilities in a public issue. Use GitHub private vulnerability reporting when available, or contact the repository owner privately with the affected component, reproduction steps, impact assessment, and suggested mitigation.
Confirmed issues are prioritized by severity and documented after remediation is available.
HelixAgent uses CodeQL, Gitleaks, Trivy, pip-audit, Dependabot, CycloneDX SBOM generation, multi-version tests, container health checks, and release-readiness validation.