Use GitHub issues for:
- False positives.
- False negatives.
- Rule documentation gaps.
- Adoption and configuration questions.
- Package or CI validation issues.
Before filing a false-positive issue, check the relevant rule page under docs/rules/ and include a minimal code sample. For private code, reduce the sample to the smallest public shape that still reproduces the diagnostic.
For security-sensitive reports, follow SECURITY.md instead of opening a public issue.