System-in-Miniature repositories are educational teaching kernels, not production services or security-hardened replacements for the systems they mirror. The projects do not provide a security response SLA, supported-version window, or guarantee of confidential handling.
For ordinary bugs, unsafe teaching examples, or semantic differences from the real system, please open a public issue in the affected project. Reports of undocumented semantic divergence are especially welcome; use the Semantic divergence issue form when available.
If a report contains credentials, personal data, or another secret, do not put that material in a public issue. Remove or rotate the secret first, then share the smallest safe reproduction through a private GitHub security advisory if the affected repository has that feature enabled.
Because these projects are educational and have no response SLA, do not rely on them for production security boundaries or time-critical remediation.