Report suspected vulnerabilities privately through GitHub Security Advisories for this repository. Include the affected version, reproduction, impact, and any known mitigation. Do not include live vessel, operator, credential, or safety-controller data.
Maintainers will acknowledge a report, assess affected versions, coordinate a fix and disclosure, and publish a signed release when remediation is ready. Security support targets the latest major release. Product integrators remain responsible for command authentication, controller fencing, secure boot/update, key management, and vulnerability response for their deployed system.