Security fixes are expected on the default branch and tagged releases derived from it.
Do not open public issues for secrets, credential exposure, or exploitable vulnerabilities. Report privately to the repository maintainer through the preferred private channel for the project.
Include:
- affected commit or release
- reproduction steps
- expected impact
- whether a live Tripo key or generated artifact is involved
- any suggested mitigation
Run:
go run golang.org/x/vuln/cmd/govulncheck@latest ./...CI also runs govulncheck in advisory mode.
See THREAT_MODEL.md for assets, trust boundaries, known threats, and recommended mitigations.