Only the following versions receive security patches:
| Version | Supported |
|---|---|
| latest (main) | ✅ |
| < latest | ❌ |
- Do not open a public issue for a security vulnerability — this exposes the problem before a fix exists.
- Instead, report it privately via the Security > Report a vulnerability tab (Security Advisories) of this repo, or by reaching out on Discord: @saiitanaa.
- Clearly describe the vulnerability, the steps to reproduce it, and its potential impact.
- You'll get an acknowledgment within 72 hours, along with an estimated timeline for a fix if the vulnerability is confirmed.
- Reports stay confidential until a fix is released.
- Once fixed, the vulnerability may be documented in the release notes, with credit to the reporter if desired.
- Any coordinated disclosure (CVE, etc.) happens after the fix is published, not before.
- This policy covers the source code of this repository.
- Third-party dependencies should be reported directly to their respective maintainers.
If your report leads to a fix, you'll be credited in the release notes (unless you'd rather stay anonymous)!