Security fixes are applied to the latest released minor version. As the project is
pre-1.0, only the most recent 0.x release is supported.
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
| < 0.1 | ❌ |
Please do not report security vulnerabilities through public GitHub issues.
Instead, report them privately via GitHub Security Advisories. This lets us discuss and fix the issue before it is publicly disclosed.
When reporting, please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce or a proof of concept
- The affected version(s)
- Any suggested mitigation, if known
You can expect an initial acknowledgement within a few days. Once the issue is confirmed and fixed, a patched release will be published and the advisory disclosed with appropriate credit, if desired.
Thank you for helping keep the project and its users safe.