| Version | Supported |
|---|---|
| latest release | Yes |
edge (main branch) |
Best effort |
| older releases | No |
Security fixes target the latest release and main. Older releases may receive patches for critical vulnerabilities on a best-effort basis.
Please report security vulnerabilities through GitHub Security Advisories.
- Include steps to reproduce, affected version, and impact assessment
- Allow up to 72 hours for an initial response
- Keep details private until a fix is released
- Unauthorized access to user data or downloads
- Remote code execution or privilege escalation
- Bypass of download filters or configuration restrictions
- Insecure handling of credentials, tokens, or session files
- Container misconfigurations that weaken security
- Social engineering attacks on maintainers
- Issues requiring physical access to the host
- Denial-of-service requiring unrealistic resources
- Known dependency vulnerabilities without practical exploitation in this project
- You report the vulnerability privately
- We investigate and develop a fix
- You receive a pre-release advisory to confirm the fix
- Fix is released with a security advisory
- You're welcome to discuss the vulnerability publicly after release
We're happy to credit reporters in release notes unless you prefer to remain anonymous.