This project is actively developed on the main branch.
Security fixes are applied to the latest codebase first.
Please do not open public issues for sensitive vulnerabilities.
Instead, use GitHub as the communication channel:
- Preferred: open a GitHub Security Advisory (private report) if available in this repository.
- Fallback: open a minimal public GitHub issue/discussion without exploit details, and request a private follow-up in maintainers' comments.
Please include:
- Affected component/service
- Vulnerability type and impact
- Reproduction steps or proof-of-concept
- Suggested remediation (if available)
Best effort targets:
- Initial acknowledgement: within 72 hours
- Triage and severity assessment: within 7 days
- Remediation timeline: shared after validation
- Secrets committed to the repository are treated as critical and should be reported immediately.
- Third-party dependency vulnerabilities may be fixed by upgrade/pinning based on risk.