Security fixes are applied to the default branch (main) and may be backported to the latest release tag when practical. Exact support windows may evolve as the project matures.
Please do not report security vulnerabilities through public GitHub issues.
Instead, report sensitive issues using one of these options:
- GitHub private vulnerability reporting (preferred if enabled on the repository): use the “Security” tab and “Report a vulnerability”.
- Email: contact the maintainers through a private channel if listed in repository metadata; if none is listed, open a GitHub issue asking for a secure contact (without disclosing exploit details).
Include:
- Description of the issue and potential impact
- Steps to reproduce or a proof of concept (if safe to share)
- Affected versions or commits, if known
Maintainers will acknowledge receipt as soon as possible and coordinate a fix and disclosure timeline.
We support good-faith security research. Do not access data that is not yours, do not degrade services, and give us reasonable time to fix issues before public disclosure.