We take security seriously. Please follow the guidance below to report vulnerabilities responsibly.
We generally support the latest commit on the main branch.
- Do not open a public issue for security vulnerabilities.
- If your repository has GitHub's "Report a vulnerability" enabled (Security Advisories), please use that to create a private report.
- If not available, open a new issue with minimal details and label it "security", and a maintainer will contact you to proceed privately.
- Provide a clear description, reproduction steps, and potential impact. Avoid sharing exploit details publicly.
- We will acknowledge receipt within 5 business days.
- We aim to provide a timeline for remediation after triage.
- We will coordinate a responsible disclosure and credit reporters who wish to be acknowledged.
Thank you for helping keep this project secure.