Security fixes are published for the latest released artifact versions unless a release note states otherwise.
Report suspected vulnerabilities privately through GitHub security advisories for
offering-protocol/odp-java. Include the affected module and version, a minimal reproduction or
affected code path, expected impact, and whether the issue is already public.
Do not open a public issue for an active vulnerability. Protocol design discussion belongs in the
odp-specs repository.
