v1.0.3
A small security patch on the 1.0 line: it clears a RustSec advisory carried by a dev/bench dependency and ships the project’s first security policy. No new features, no behaviour changes, and the machine contracts frozen in 1.0.0 are untouched.
Security
Section titled “Security”- ⬆️ Bumped
crossbeam-epoch0.9.18→0.9.20to clear RUSTSEC-2026-0204 (invalid pointer dereference), which was failing thecargo audit --deny warningsCI gate. It reaches the tree only as a dev/bench dependency (criterion → rayon → crossbeam-deque); no runtime code is affected (#360, #361). - 🔒 Added a
SECURITY.mdpolicy documenting supported versions (the 1.0.x line) and a private vulnerability-reporting flow via GitHub advisories, with an email fallback (#360, #361).