Security fixes should target main unless maintainers document a release branch.
Please do not open public issues with exploit details, private case data, secrets, or vulnerable sample documents.
Report security concerns by opening a minimal GitHub issue that says a private report is available, or contact the maintainer through the public profile linked from the repository. Include:
- A short description of the issue.
- Affected platform or component.
- Reproduction steps using synthetic data only.
- Impact assessment and any suggested mitigation.
Ross is designed around private legal workflows. Contributions must not weaken the local-first boundary for private matter files. If a feature sends data to a network service, it must be explicit, justified, documented, and avoid private case material by default.