Security fixes are prioritized for the latest release line.
Please do not open public issues for security vulnerabilities.
Use one of the following private channels:
- Repository security advisory (recommended)
- Maintainer contact email defined by your organization
Please include:
- Vulnerability description
- Impact assessment
- Reproduction steps or PoC
- Affected versions and environment
If you identify potential commercial-use compliance risks or licensing conflicts, report them through the same private channels.
- Initial triage: within 3 business days
- Confirmation and scope assessment
- Patch preparation and verification
- Coordinated disclosure and release note update
After a fix is available, we will publish a changelog/release note with impact summary and upgrade guidance.