Only the latest published release candidate receives fixes during the preview period.
Use GitHub private vulnerability reporting when available. Do not open a public issue containing working credentials, private user data, or a weaponized proof of concept.
Include the affected asset or manifest ID, version, reproduction steps, expected impact, and whether the issue crosses the Desktop/HUB profile boundary.
The HUB favors transparent execution over opaque blocking. It displays publisher, source, license, certificate/signature state, requested privilege, network use, validation evidence, and known limitations. These declarations help users make decisions; they are not a guarantee that third-party software is harmless.