CUDA-JS-Tensor is pre-release and has no supported production version. Report suspected vulnerabilities through GitHub's private vulnerability reporting form. If that route is unexpectedly unavailable, open only a minimal issue that requests a private maintainer contact without publishing exploit details, credentials, machine identifiers, or sensitive artifacts.
Public tensors and errors must not expose native pointers, handles, ordinals, provider paths, generated CUDA source, environment secrets, or unbounded backend logs.