Only the latest tagged release receives security fixes. Until the project publishes a stable release, treat every build as pre-1.0.
Do not open a public issue, discussion, or pull request for vulnerabilities.
Use this repository's private Security → Report a vulnerability form (GitHub Security Advisories) and include:
- the affected version and operating system;
- reproduction steps and expected impact;
- relevant logs with secrets, tokens, addresses, and identifiers removed;
- whether coordinated disclosure requires an embargo.
We aim to acknowledge reports within 72 hours, provide an initial assessment within 7 days, and coordinate publication after a fix is available.