The project currently supports the latest main branch and the most recent release line.
Please do not report security vulnerabilities through public GitHub issues or discussions.
Instead, report them privately via one of the following:
- create a private security advisory on GitHub, if repository settings permit it
- contact the maintainers directly through the repository's private contact channel
Please include:
- a description of the issue
- affected versions or branch
- reproduction steps or proof of concept
- the impact and risk assessment
- any suggested mitigation
We ask that you allow us a reasonable amount of time to investigate and address the issue before making it public.
We will:
- acknowledge receipt when possible
- assess the report and determine impact
- work on a fix in a private branch when needed
- release a patched version and credit the reporter when appropriate
We appreciate responsible disclosure and will handle reports with confidentiality.