Security fixes are applied to the latest published Context release.
Do not open a public Issue for a suspected vulnerability. Use GitHub's private vulnerability reporting and include:
- the affected version and component;
- reproduction steps or a proof of concept;
- the security impact;
- any suggested mitigation;
- whether the issue has been disclosed elsewhere.
Relevant reports include unsafe file access, command execution, path traversal, source or credential disclosure, authority bypasses, review-gate bypasses, package integrity failures, and vulnerabilities in the CLI, SDK, extractors, plugins, or published artifacts.
General support questions and non-security bugs should use GitHub Discussions or Issues.