Security fixes are provided for the latest released minor version. Older versions are not maintained; please upgrade before reporting.
| Version | Supported |
|---|---|
| 0.7.x | ✅ |
| < 0.7 | ❌ |
Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.
Report vulnerabilities privately through GitHub's built-in private vulnerability reporting:
This opens a private advisory visible only to the maintainers and to you.
This project is maintained on a best-effort basis. Reports are reviewed and addressed as maintainer availability allows; there is no guaranteed response time. We will engage with the private advisory as we triage and work on a fix.
We follow coordinated disclosure. Please give the maintainers a reasonable opportunity to investigate and release a fix before disclosing the issue publicly. We will coordinate the timing and content of any public disclosure with you through the private advisory.
This policy covers the code in this repository. Vulnerabilities in third-party dependencies should be reported to the respective upstream projects; if a dependency issue affects this project specifically, you may still report it here so we can track remediation.