Please report vulnerabilities through GitHub private vulnerability reporting. Do not open a public issue for an undisclosed vulnerability.
Include the affected commit or candidate run, the Sallyport workflow SHA, the expected security boundary, and a minimal reproduction when possible.
sallytest is a downstream acceptance fixture. Sallyport's threat model defines the protocol guarantees and out-of-scope configurations.