| Version | Supported |
|---|---|
| Latest | ✅ |
| Older | ❌ |
Only the latest release receives security fixes. Please update to the latest version before reporting a vulnerability.
Please do not report security vulnerabilities through public GitHub issues.
Use GitHub's private vulnerability reporting to disclose security issues confidentially:
Include as much detail as possible:
- Description of the vulnerability and its potential impact
- Steps to reproduce or proof-of-concept
- Affected versions
After you submit a report:
- You will receive an acknowledgment within 72 hours.
- We will investigate and keep you informed of the progress.
- Once a fix is ready, we will coordinate a disclosure timeline with you.
- A public security advisory will be published after the fix is released.
We appreciate responsible disclosure and thank you for helping keep this project secure.