This repository has not published a supported product release. Security reports still apply to the checked-in Protocol validators, generated contracts, and tooling.
Once packages are published, this file will list the versions that receive fixes.
Please do not open a public issue for a suspected vulnerability.
Report it privately through GitHub Security Advisories on this repository, or follow the process used by oceanbase/powercontext.
Include:
- A description of the issue and its impact
- Reproduction steps or a proof of concept
- Affected package, commit, or command
@powercontext/protocoland@powercontext/clientmust not depend on native addons.- Contract snapshots and conformance fixtures are generated. Hand edits are rejected.
- Dependency licenses and high/critical advisories are CI gates. See docs/policies/dependencies.md.