| Version | Supported |
|---|---|
| Latest | ✅ |
| < Latest | ❌ |
Only the most recent release receives security updates.
Do not open a public GitHub issue for security vulnerabilities.
- Go to the Security tab of this repository
- Click "Report a vulnerability"
- Fill in the details and submit
If private vulnerability reporting is not available, email the maintainers directly. Contact information can be found in the repository's commit history.
- Description of the vulnerability
- Steps to reproduce
- Affected versions
- Potential impact
- Acknowledgment: within 14 days of report
- Assessment: severity evaluation and fix timeline provided after acknowledgment
- Fix target: within 90 days for most vulnerabilities
We follow coordinated disclosure:
- Reporter submits vulnerability privately
- We acknowledge and assess the report
- We develop and test a fix
- Fix is released with a security advisory
- Reporter is credited (unless they prefer anonymity)
Please allow us reasonable time to address the issue before any public disclosure.