Security fixes target the latest published release and the default branch of actively maintained projects. A repository may define a more specific support window in its own security policy.
Do not open a public issue for a vulnerability or include sensitive data in a discussion.
Use Security → Report a vulnerability in the affected repository when private vulnerability reporting is available. Otherwise, email bunny@xiyo.dev with:
- the affected repository and version or commit;
- the security impact;
- minimal reproduction steps using synthetic data;
- any suggested mitigation.
Do not attach credentials, personal messages, calendar contents, production databases, or unrelated private data. You will receive an acknowledgement after the report is reviewed; disclosure timing will be coordinated before details are made public.