We take the security of our applications seriously. Only the latest modern iterations of the codebase are actively maintained with security patches, vulnerability resolutions, and dependency updates.
| Version | Supported | Notes |
|---|---|---|
| 3.x.x | ✅ Yes | Active development, security audits, and patch stream. |
| 2.x.x | ❌ No | End of Life (EOL). Upgrade immediately to v3. |
| 1.x.x | ❌ No | End of Life (EOL). Unsupported legacy codebase. |
We have enabled Private Vulnerability Reporting directly on this repository. This allows you to safely disclose security vulnerabilities directly to the maintainers through GitHub without exposing the details publicly.
- On GitHub.com, navigate to the main page of this repository.
- Click on the Security and quality tab located under the repository name.
- Click Report a vulnerability to open the advisory form.
- Fill out the form with a detailed summary, step-by-step instructions, or a proof-of-concept (PoC) to help us reproduce and resolve the issue.
- Click Submit report.
- Triage & Validation: The repository maintainers will review your private report immediately, collaborate with you inside a private advisory workspace if additional details are needed, and validate the vulnerability.
- Patch Stream: If verified, a patch will be securely developed and deployed straight into the
v3branch workspace. - Responsible Disclosure: We appreciate your help keeping the user base secure and kindly request that you coordinate with us through the GitHub Advisory system before publishing details or disclosing the vulnerability publicly.