Security
Supported Versions
Only the latest release is actively supported.
| Version | Status |
|---|---|
| Latest release | ✅ Supported |
| Older releases | ❌ Unsupported — upgrade to latest |
main branch | ⚠️ Best effort (development) |
Reporting a Vulnerability
Please do not report security vulnerabilities through public GitHub issues.
Instead, report them privately via GitHub Security Advisory.
- Go to the repository's Security tab
- Click Report a vulnerability
- Fill out the form with details of the issue
You can expect an acknowledgement within 48 hours and a resolution within 90 days.
Disclosure Policy
- Report vulnerabilities to the maintainers through a private channel first.
- The maintainers prepare a fix before public disclosure.
- The maintainers disclose the issue after they release a fix or after 90 days, whichever is sooner.