Security fixes target the latest release of jsonata4java-benchmark. Older tags are not routinely patched unless a fix is trivial to backport.
Use GitHub private vulnerability reporting when it is enabled. Otherwise email furyx.ds@gmail.com.
Do not disclose suspected vulnerabilities in public issues, discussions, or pull requests.
Include the affected version or commit, impact, reproduction steps, and any suggested mitigation. Remove credentials, tokens, account identifiers, and personal data from the report.
You should receive an acknowledgement within 7 days. Confirmed critical and high severity issues are prioritized for remediation within 30 days; lower severity issues are scheduled according to risk.