Security

Current Baseline

Developer Dashboard now applies these runtime protections in the active codebase:

Repository Hygiene

The active tree outside the read-only older reference tree is kept free of:

That older reference tree remains read-only reference material and is not modified or committed as part of the active runtime.

Verification

Run these checks:

dashboard doctor
dashboard doctor --fix
prove -lr t

Private Reporting

The published root security policy lives in SECURITY.md and currently directs private reports to: