Report vulnerabilities privately to the project owner before public disclosure.
CodeGraph reads untrusted repositories. Parsers run without network access by
design, generated output is never executed, and HTTP binds to loopback by default.
Treat graph artifacts as untrusted until codegraph verify succeeds.