This repository follows the Parity security policy. Report vulnerabilities through the channels in that policy or this repository's GitHub private vulnerability reporting. Do not open public issues for unpatched vulnerabilities.
Runtime boundaries are security-sensitive. Reports involving guest memory access, hostcall bounds, path traversal, asset limits, GPU wire validation, compiler/interpreter parity, or worker lifecycle cleanup should include the affected source revision and backend.