| Version | Supported |
|---|---|
| Latest release | Yes |
| Older releases | No |
Only the latest release receives security updates. Users should always upgrade to the most recent version.
Please do not report security vulnerabilities through public GitHub issues.
Report vulnerabilities via GitHub Security Advisories. This allows private discussion and coordinated disclosure.
If you cannot use Security Advisories, contact the maintainers listed in CODEOWNERS.
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledge: within 2 weeks
- Assess: within 1 month
- Fix: timeline depends on severity, communicated during assessment
We follow coordinated disclosure. Please allow us reasonable time to address the issue before any public disclosure.