If you discover a security vulnerability, please report it responsibly:
- Do not open a public issue.
- Contact the maintainer via the repository issue tracker with a private security advisory.
- Include a description of the vulnerability, steps to reproduce, and potential impact.
- Acknowledgement within 48 hours.
- Assessment and fix within 7 days for critical issues.
- Public disclosure after a fix is available.
This policy applies to the latest release of IntentLock Intent-to-Commit.