Security fixes are applied to the current master release branch and are
integrated through develop. Published image tags receive fixes when supported
by the current release line.
Please do not open a public issue for suspected security vulnerabilities.
Until a dedicated security contact is published, report privately to the repository owner through GitHub. Include:
- affected version or commit
- upstream
mochadcommit if known - host and container deployment context
- steps to reproduce
- expected impact
Do not include private host paths, credentials, or USB device serial details in public reports.