Security fixes will generally be applied to the latest release only, unless otherwise noted in the project’s README or Discussions.
If you discover a security issue or vulnerability:
- Do not open a public issue or pull request.
- Instead, please email: [email protected]
- Include as much detail as possible:
- Affected version(s)
- Reproduction steps
- Potential impact
- Suggested mitigation or patch (if any)
We aim to respond promptly, typically within a few business days. If the issue is confirmed, we’ll coordinate a disclosure process and patch timeline.
We follow responsible disclosure. Public disclosure will occur after:
- A patch is released or mitigation is documented
- A mutually agreed-upon timeline with the reporter
- Or, no response from the reporter within 30 days of our patch
Thank you for helping keep this project and its users secure.