Security fixes are provided for the active development branch.
| Version | Supported |
|---|---|
main |
Yes |
| Older tags/releases | No |
Do not open public issues for security vulnerabilities.
Use one of these private channels:
- GitHub Security Advisory (preferred)
- Direct maintainer contact, if published in the repository profile
Please include:
- clear description of the issue
- impact and attack scenario
- reproduction steps or proof of concept
- suggested mitigation (if available)
- Initial triage: within 72 hours
- Status update after validation: within 7 days
- Fix timeline: depends on severity and complexity
After a fix is available, maintainers may publish a coordinated disclosure with remediation details and affected versions.