docs/security/incident-response.md
We monitor security signals from:
Initial triage:
SECURITY.md scope and out-of-scope rules.Severity guide:
main, then implement and validate a patch with regression coverage.We communicate through:
Disclosure policy:
After shipping the fix: