Only the latest main branch is actively supported for security updates.
If you discover a security issue:
- Do not open a public issue with exploit details or leaked secrets.
- Contact the NaNLABS Technology team through internal channels, or email
technology@nanlabs.comif you are an external reporter. - Include reproduction details, impact, and affected files when safe to share.
- No credentials are stored in source control.
- MCP templates (when present) use environment-variable placeholders only.
- CI runs
scripts/secret-scan.shplus GitHub secret scanning / push protection. - Public content must pass
docs/PUBLIC_CONTENT_POLICY.mdbefore merge.