Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, send a report to security@biscuitsec.org.
Include as much of the following as you can:
- A description of the vulnerability and its impact
- Steps to reproduce, or a proof-of-concept
- The version of the bundle and any relevant environment details
You will receive an acknowledgement within 14 days. We will work with you to confirm the issue, prepare a fix, and coordinate disclosure timing. Public disclosure happens after a fix is released.
Until v1.0.0, only the latest minor version receives security fixes.