Skip to main content

Security

Supported Versions​

Only the latest release is actively supported.

VersionStatus
Latest release✅ Supported
Older releases❌ Unsupported — upgrade to latest
main branch⚠️ Best effort (development)

Reporting a Vulnerability​

Please do not report security vulnerabilities through public GitHub issues.

Instead, report them privately via GitHub Security Advisory.

  1. Go to the repository's Security tab
  2. Click Report a vulnerability
  3. Fill out the form with details of the issue

You can expect an acknowledgement within 48 hours and a resolution within 90 days.

Disclosure Policy​

  • Report vulnerabilities to the maintainers through a private channel first.
  • The maintainers prepare a fix before public disclosure.
  • The maintainers disclose the issue after they release a fix or after 90 days, whichever is sooner.