Security fixes target the current released ProjectAtlas version and the active main branch. Older versions are reviewed case by case when the impact is high or an installer/release artifact is affected.
Report vulnerabilities through GitHub Security Advisories for this repository. If that is unavailable, contact the repository owner directly. Do not post exploit details, secrets, private logs, or unreleased vulnerability information in public issues, pull requests, or discussions before coordinated disclosure is complete.
Include the affected ProjectAtlas version, platform, install path or installer script when relevant, reproduction steps, expected impact, and logs with secrets or local credentials removed. For release artifact or installer issues, include the archive name, checksum evidence if available, and whether the issue affects Windows, Linux, macOS, or all platforms.
Maintainers will triage private reports, ask for missing reproduction details when needed, and coordinate a fix and disclosure path before public details are published. Public release notes should describe the impact and fixed version without exposing unnecessary exploit detail.