| Version | Supported |
|---|---|
| 2.x | ✅ |
| < 2.0 | ❌ |
Do not open a public issue for security vulnerabilities.
Please report vulnerabilities through GitHub Security Advisories. This ensures the report remains private while we work on a fix.
Include the following in your report:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment: Within 48 hours of receipt
- Initial assessment: Within 1 week
- Fix development: Depends on severity; critical issues are prioritized
We follow coordinated disclosure:
- Reporter submits vulnerability via GitHub Security Advisories.
- We acknowledge and begin investigation.
- We develop and test a fix.
- We release the fix and publish a security advisory.
- Public disclosure occurs after the fix is released, with a maximum 90-day window from initial report.
We credit reporters in the advisory unless they prefer to remain anonymous.