Do not report security vulnerabilities in a public issue. Report them through the Conductor private security advisory channel.
Include the affected Java SDK artifact and version, a minimal reproduction, impact, and any mitigation you identified.
Security fixes are applied to the current maintained release line. Please upgrade to the latest published SDK release before reporting behavior that may already be fixed.
For Conductor server support and vulnerability policy, see the upstream security policy.