This project is provided "AS IS", without warranties or guarantees of any kind, including any warranty that it is secure, free of vulnerabilities, or suitable for any particular purpose or production use.
Users are responsible for evaluating, deploying, configuring, and operating this software in a manner appropriate for their own environment and risk tolerance.
Unless otherwise stated, security fixes, when provided, are made only for the latest version of the project.
| Version | Supported |
|---|---|
| Latest | ✅ |
| Older releases | ❌ |
If you believe you have discovered a security vulnerability, please do not create a public GitHub issue.
Instead, use GitHub's Private Vulnerability Reporting feature to submit your report privately.
Please include, where possible:
- A description of the issue
- Steps to reproduce
- The affected version or commit
- Any relevant logs, screenshots, or proof-of-concept code
- The potential impact of the vulnerability
While all reports are appreciated, this project is maintained on a best-effort basis. There is no guarantee of a response, remediation, or security update.
Please practice responsible disclosure and allow reasonable time for review before publicly disclosing any vulnerability.
Security reports related to the project, its dependencies, build process, configuration, authentication, authorization, data handling, integrations, or other security-relevant behavior are welcome.