This is an open-source project. Security fixes are applied on the default branch (main) and included in the next release.
| Version | Supported |
|---|---|
main |
Yes |
| Older snapshots/commits | No |
Please do not open public issues for security reports.
Use one of these channels:
- Open a private GitHub Security Advisory (preferred).
- Contact the maintainers directly and include "SECURITY" in the subject.
When reporting, include:
- Affected component and version/commit.
- Reproduction steps or proof of concept.
- Impact assessment (confidentiality/integrity/availability).
- Suggested mitigation, if available.
- Initial acknowledgment: within 3 business days.
- Triage decision: within 7 business days.
- Regular updates: at least weekly until resolution.
We will coordinate disclosure timelines with the reporter and publish a fix note when appropriate.