The current main branch is the supported development version until the project publishes a versioned support policy.
Do not disclose suspected vulnerabilities in a public issue, discussion, pull request, screenshot, or log.
Use GitHub private vulnerability reporting from the repository's Security page when available. Otherwise email rajesh@hyperoot.dev with a concise description and request a private channel before sending sensitive material.
Include, when safe and relevant:
- the affected commit or deployment;
- impact and affected users;
- minimal reproduction steps;
- relevant browser, operating system, and configuration;
- known mitigations; and
- whether the issue has been disclosed elsewhere.
Remove credentials, tokens, personal information, private content, and unrelated logs. A proof of concept is welcome but not required.
The maintainer will make a reasonable effort to acknowledge the report, assess impact, and coordinate remediation or disclosure. No fixed response or remediation timeline is guaranteed.
Keep details confidential until a fix, mitigation, or coordinated disclosure plan is available. Accepted reports may be managed through a private GitHub security advisory.