Security policy¶
Report suspected credential disclosure, cross-property data access, Shopper privacy leakage, unsafe SQL configuration, dependency compromise, or unbounded resource behavior privately to the repository maintainer. Use synthetic data and a minimal reproducer; do not include production catalogs, interactions, recommendation payloads, tokens, or secrets.
This repository is currently internal and has no public vulnerability-reporting address or release channel. Establish those before making the project public.