If you discover a security vulnerability in this project, please report it through GitHub Security Advisories. This ensures your report is handled privately and responsibly.
Do not open a public issue for security vulnerabilities.
When reporting a vulnerability, please provide:
- A clear description of the issue.
- Steps to reproduce the vulnerability, if applicable.
- The affected files, schemas, or components.
- The potential impact (e.g. data exposure, schema bypass, trust model weakness).
In the context of this project, security issues may include:
- Schema design flaws that could allow invalid or malicious data to pass validation.
- Issues that could undermine the trust model or integrity of credential data.
- Exposure of sensitive information through sample data or documentation.
- We aim to acknowledge reports within 5 working days.
- We will work with you to understand and validate the issue.
- Fixes will be applied to the
mainbranch. There is no backporting to previous versions.
Only the latest version on the main branch is actively maintained.