Report suspected vulnerabilities privately. Use
[GitHub Security Advisories](https://github.com/brian-c-moore/automation-structures/security/advisories/new)
and include the affected crate version, the public API call or input that triggers the problem,
the expected invariant, and a minimal reproduction so the failure can be checked.
Keep undisclosed vulnerabilities out of public issues.