Please report vulnerabilities through GitHub private vulnerability reporting for this repository. Do not publish credentials, exploit details or identifiers from a real deployment in an issue.
Security invariants include one-job worker destruction, no host socket passthrough, fail-closed identity reconciliation, bounded diagnostics, credential-free warm capacity and strict public/private separation.
Only the current default branch and published releases are supported.