We maintain the latest main branch. Report vulnerabilities against main.
Please report security issues privately. Do not create a public issue.
- Open a security advisory draft in GitHub (Security > Advisories), or
- Email the maintainers listed in the repository.
We will acknowledge receipt within 72 hours and work on a fix.
- Secrets exposure, authentication bypass, privilege escalation
- Injection, XSS, CSRF, SSRF
- Insecure defaults and misconfigurations
- Denial of service without a clear fix
- Issues requiring unrealistic preconditions