Security fixes target the current OpenSw default branch. Older APKs and inherited upstream builds receive fixes on a best-effort basis and should not be treated as supported releases.
Use GitHub private vulnerability reporting for vulnerabilities in OpenSw. Include the affected commit or build ID, impact, reproduction steps and the smallest safe proof of concept. Do not attach games, keys, firmware, saves, personal paths or other copyrighted/private data.
Do not open a public issue for an unpatched vulnerability. A maintainer should acknowledge a private report within seven days, validate severity and coordinate disclosure after a fix is available.
Security reports about upstream Eden code may also need coordinated disclosure to the upstream project. OpenSw will preserve reporter credit unless anonymity is requested.