Security fixes are provided for the 1.0.x stable line and, until 1.0.0 is tagged, for the
latest 0.9.x line.
| Version | Supported |
|---|---|
1.0.x |
yes |
latest 0.9.x |
yes (until 1.0.0 is tagged) |
| older minor lines | no |
pre-0.1.0 commits |
no |
Do not open public GitHub issues for security vulnerabilities.
Use GitHub's private vulnerability reporting flow for this repository
(Security tab -> Report a vulnerability).
Include:
- affected commit/tag/version
- reproduction steps or proof of concept
- impact assessment
- suggested mitigation (if known)
- Initial triage acknowledgment target: within 7 days
- Confirmed issues are fixed as soon as practical and documented in
CHANGELOG.md - Public disclosure happens after a fix is available or a mitigation is documented