Responsible disclosure
Guidelines will be published with the first public repositories.
Security
A dedicated security contact will be published before the first public release.
Guidelines will be published with the first public repositories.
Reporting channels will be published before public release.
Supported versions will be listed after public releases exist.
Security update notifications are planned for future self-hosted products.
Projects are intended to use repeatable builds and documented dependency policies.
Self-hosted product data is intended to remain under the administrator's control.
Telemetry is planned to be opt-in and disabled by default.