Skip to content

Latest commit

 

History

History
42 lines (32 loc) · 1.86 KB

File metadata and controls

42 lines (32 loc) · 1.86 KB

Security Policy

Reporting Security Issues

We take the security of our project seriously. If you believe you have found a security vulnerability, please report it to us privately. Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Instead, please report them via:

Reporting Process

  1. Submit Report: Use one of the above channels to submit your report
  2. Response Time: Our team will acknowledge receipt of your report within 14 business days.
  3. Collaboration: We will collaborate with you to understand and validate the issue
  4. Resolution: We will work on a fix and coordinate the release process

Disclosure Policy

  • Please provide detailed reports with reproducible steps
  • Include the version/commit hash where you discovered the vulnerability
  • Allow us a 90-day security fix window before any public disclosure
  • After patch is released, allow 30 days for users to update before public disclosure (for a total of 120 days max between update time and fix time)
  • Share any potential mitigations or workarounds if known

Supported Versions

Only the following versions are eligible for security updates:

Version Supported
Latest release on main branch Yes
Development commits (pre-release) Yes

Security Best Practices

When using this project:

  1. Always use the latest stable version
  2. Review security advisories before updating
  3. Follow our security documentation and guidelines
  4. Keep your dependencies up to date

Past Security Advisories

For a list of past security advisories, please visit our Security Advisory Page.


Last updated: December 2025