Security fixes are applied to the latest released version. Older versions are not maintained — please upgrade to the most recent release before reporting an issue.
| Version | Supported |
|---|---|
| 0.6.x | ✅ |
| < 0.6 | ❌ |
Please do not report security vulnerabilities through public GitHub issues.
Instead, report them privately using one of the following:
- GitHub Security Advisories — use the "Report a vulnerability" button under the repository's Security tab (preferred).
- Email — opensource.simon@gmail.com
Please include as much of the following as you can:
- The affected module(s) and version (
qr-code,qr-code-svg, orqr-code-app). - A description of the vulnerability and its potential impact.
- Steps to reproduce, ideally a minimal proof of concept (e.g. the input/payload, image, or base64 string that triggers the issue).
- Any suggested mitigation, if you have one.
- I will acknowledge your report as soon as possible, typically within a few days.
- I will keep you informed about the progress toward a fix.
- Once a fix is released, the advisory will be published and your contribution credited, unless you prefer to remain anonymous.
Thank you for helping keep this project and its users safe.