Please report suspected security vulnerabilities privately via GitHub Security Advisories. Do not open public issues for security reports.
We will acknowledge receipt within 72 hours and aim to provide a remediation timeline.
State which versions/branches are supported here (e.g., main is actively maintained).
- Triage and acknowledge within 72 hours
- Provide status updates until fixed
- Coordinate disclosure with the reporter
We prefer coordinated disclosure. Please avoid public disclosure until a fix is available or coordinated with the security contact.
(Optional) Provide a PGP key fingerprint or upload a key for encrypted reports.
This repository uses GitHub Security Advisories as the private reporting channel for vulnerability disclosures.