Only the latest stable release receives security fixes. If no stable release has been made, patches are applied to main.
Please do not open a public pull request or issue for security vulnerabilities.
Use the "Report a vulnerability" button on the repository's Security tab (GitHub Private Vulnerability Reporting). This opens a private draft advisory visible only to maintainers.
Include:
- A description of the vulnerability and its potential impact
- Steps to reproduce or a proof-of-concept
- Any suggested remediation if you have one
You can expect an acknowledgement within 48 hours and a resolution timeline within 5 business days of triage.