Security fixes target the latest tip of the dev branch and any tagged releases
published from this repository.
Do not open a public GitHub issue for an unfixed vulnerability.
Prefer a private GitHub Security Advisory on this repository when available. Otherwise email contact@interchouette.net with a clear description, impact, and reproduction steps when possible.
We will acknowledge receipt and follow up. Do not expect a fixed SLA.
Local and CI dependency checks are documented in
SUPPLY-CHAIN.md. That document is not a vulnerability
reporting channel.