Security fixes are targeted at:
- the latest tagged release
- the
mainbranch
Older releases may receive no fixes.
Do not open a public GitHub issue for a vulnerability with active exploit details.
Preferred path:
- use GitHub Private Vulnerability Reporting for this repository if it is enabled
If private reporting is not available in the repository UI:
- open a minimal public issue without exploit details
- ask for a private contact path before sharing proof-of-concept material
Please include:
- affected version
- impact
- reproduction steps
- any suggested mitigation
We will acknowledge receipt, validate the report, and coordinate disclosure once a fix or mitigation is available.