| Version | Supported |
|---|---|
| 6.x | β |
| < 6.0 | β |
Users on an unsupported major version should upgrade to the latest release to continue receiving security fixes.
Please do NOT open a public GitHub issue for security vulnerabilities.
Use the private GitHub Security Advisory form instead:
π Report a vulnerability privately
We will:
- Acknowledge your report within 48 hours.
- Provide an estimated fix timeline within 5 business days.
- Release a patch and publish a coordinated disclosure once the fix is available.
| In scope | Examples |
|---|---|
| β | Prototype pollution, ReDoS, arbitrary code execution via crafted input |
| β | Supply chain issues (malicious dependency, compromised release) |
| β | Incorrect locale output for a specific number (file a regular issue) |
| β | Missing locale or currency support (file a regular issue) |