Security
Start with the threat model and the reporting policy. Do not file public issues for exploitable vulnerabilities.
Threat model -- what LOTA protects, what it enforces, and what is out of scope.
Security reporting -- how to report a vulnerability.
Reproducible builds -- rebuild a release and verify its signature.
Attestation CA signing key -- key ceremony, rotation, and topology.