If you discover a security vulnerability, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, please email the maintainers directly or use GitHub's private vulnerability reporting feature.
| Version | Supported |
|---|---|
| latest | ✅ |
- Acknowledgment: Within 48 hours
- Initial assessment: Within 1 week
- Fix/patch: Depends on severity, typically within 2 weeks for critical issues
This policy covers the codebase in this repository. Third-party dependencies are governed by their own security policies.