Follow the organization's security policy.
Report suspected vulnerabilities privately using GitHub private vulnerability reporting in the affected repository, if available. If no private reporting option is available, open an issue containing no sensitive details and request a private channel. Do not post a proof of concept, credentials, proprietary data, or security-sensitive logs in a public issue or discussion.
There are no installer releases yet. This repository does not establish a supported-version window or guaranteed response time. Reports affecting the SA SDK or another Hexagon product are coordinated through the project's private triage process and Hexagon focal under the organization policy.