Security fixes are evaluated for the latest active branch and the current release line.
| Version | Supported |
|---|---|
1.0.x |
Yes |
< 1.0.0 |
No |
- Do not open public GitHub issues for security vulnerabilities.
- Use GitHub Security Advisories when available to report sensitive findings privately.
- If private reporting is not available, contact the repository maintainer directly through an agreed private channel.
- A concise description of the issue
- Impact and affected area
- Reproduction steps or proof of concept
- Suggested remediation if known
The team will review reports, validate the issue, and coordinate remediation before public disclosure.