Reference
Security
Security reporting, supported development boundaries, and repository controls.
Please report vulnerabilities privately through GitHub security advisories. If GitHub is unavailable, contact jon@jonbogaty.com with the subject Strata security report.
The repository uses dependency review, Dependabot, CodeQL, secret scanning with push protection, pinned GitHub Actions, and least-privilege workflow permissions. Release publishing and documentation deployment run only from trusted release state and use OIDC where the registry supports it.
See the full security policy for supported versions and disclosure guidance.
