The project currently supports the latest released version on the main branch.
Please report security vulnerabilities privately to the maintainers using the repository security advisory system or by emailing the project owner through the GitHub profile linked in the repository.
Please do not disclose the issue publicly until a fix has been prepared and announced.
We ask reporters to:
- Confirm the issue is reproducible and provide a concise description.
- Avoid privacy violations or destruction of data.
- Allow a reasonable time for a fix to be prepared.
- Coordinate disclosure timing with maintainers.
We will acknowledge receipt within 5 business days and provide a remediation plan when available.