Report privately through this repository's GitHub "Report a vulnerability" form (Security tab → Advisories), never as a public issue.
Scope: this repository (opensoft/openXdox), the assembly root of the
openXdox project. The two legs, opensoft/openXdox-spec and
opensoft/openXdox-code, each carry their own SECURITY.md with the same
path for reports scoped to that repository specifically.
Expected acknowledgement within 7 days.