Yamazaki has no released or supported production versions. The project is an early-stage public project with a validated internal, controlled-network read-only POC and no supported production deployment.
Security reports about repository configuration, documentation, future design, or later implementations are still welcome.
Use GitHub's private vulnerability reporting to contact the maintainers securely.
Do not disclose vulnerability details, credentials, production data, internal endpoints, or exploit steps in a public Issue, Discussion, or pull request.
Include the following information when available:
- A clear description of the issue and affected behavior.
- Reproduction steps or a minimal proof of concept.
- Potential impact and preconditions.
- Relevant versions, configurations, logs, or evidence with secrets removed.
- Suggested mitigations or fixes, if known.
Maintainers may request additional information through the private advisory. Public disclosure should occur only after a fix or mitigation is available and the disclosure timing has been coordinated.