We provide security fixes for the latest published release and the current main branch.
| Version | Supported |
|---|---|
| Latest release | ✅ |
main |
✅ |
| Older releases | ❌ |
Please do not open public issues for security vulnerabilities.
Use GitHub private vulnerability reporting:
When reporting, include:
- A clear description of the issue and potential impact
- Reproduction steps or proof-of-concept
- Affected versions/commit SHA
- Any suggested remediation
Please avoid including real credentials, tokens, or private customer data in reports.
- Acknowledgement: within 72 hours
- Initial triage update: within 7 days
- Remediation target: based on severity and complexity
We follow responsible disclosure:
- Report privately through GitHub advisories.
- Allow time for investigation and fix development.
- Coordinate disclosure timing after a fix is available.
Thank you for helping keep this project and its users safe.