| Version | Supported |
|---|---|
| 1.2.x | ✅ |
| 1.1.x | ❌ |
| 1.0.x | ❌ |
Please do not open a public issue for security vulnerabilities.
Instead, report them privately by emailing security@example.com with:
- A clear description of the issue
- Steps to reproduce
- Likely impact
- Suggested fix (if any)
We aim to acknowledge reports within 3 business days and will work with you to triage and remediate the issue.
We request that you give us a reasonable amount of time to fix the issue before publicly disclosing it. If you follow this policy in good faith, we consider your research authorized and will not pursue legal action related to your report.
In scope: this repository, published packages, and the production deployment at https://example.com.
Out of scope: third-party dependencies, intentionally vulnerable test code, and denial-of-service testing.