Security fixes are made for the latest published release. Users should upgrade to the newest version before reporting an issue that may already be resolved.
| Version | Supported |
|---|---|
| Latest published release | Yes |
| Older releases | No |
Do not open a public issue, discussion, or pull request for a suspected vulnerability. Use GitHub's private vulnerability reporting to send the report directly to the maintainers.
Please include:
- the affected SDK version and environment;
- the security impact and who could be affected;
- minimal reproduction steps or a proof of concept; and
- any suggested mitigation, if known.
Maintainers will keep the report private while validating it, coordinate a fix and release when warranted, and credit reporters who request credit. Please allow time for a fix to reach users before publishing details. This project does not promise a bounty or other reward for reports.