Please do not open a public issue for a security report. Two channels, in order of preference:
- GitHub private vulnerability reporting, from this repository's Security tab. The report arrives attached to the repo with a draft advisory and a CVE request path already in place.
- Email
security@simtabi.com, if you would rather not use GitHub or do not have an account.
Either way, include a description of the issue, the affected version, and steps to reproduce.
You will receive an acknowledgement within three working days. We aim to ship a fix, or a documented mitigation, within 30 days of confirming the report, and will credit you in the release notes unless you ask otherwise.
While the package is pre-1.0, only the latest tag receives security fixes.