Please report suspected security vulnerabilities privately — do not open a public issue, pull request, or discussion for a security report.
Email security@coderoast.fr with:
- a description of the issue and its impact,
- steps to reproduce (a minimal proof-of-concept if possible),
- the affected version or commit.
We aim to acknowledge reports within 3 business days and to share a remediation timeline after triage. We practise coordinated disclosure: please allow a reasonable window for a fix to ship before any public disclosure. With your consent, we will credit you in the advisory.
Security fixes target the latest released version (the 1.4.x line). Earlier
versions are not maintained.