We prioritize security fixes for the main branch and the latest published
release of each affected package. Reports affecting older versions are welcome
and will be assessed case by case. Please include the package, version, and
commit you tested.
Please submit reports through GitHub private vulnerability reporting or choose Security → Advisories → Report a vulnerability on the repository. Do not post vulnerability details in public issues, discussions, or Discord.
If you cannot access the private reporting form, open a public issue asking for a private contact method without including technical details.
Include the affected component and version, the impact, and reproducible steps or a proof of concept. Avoid accessing or changing data that is not yours, and stop testing if it could disrupt a service or expose another person's data.
We aim to acknowledge reports within five business days. We will investigate with the reporter, work toward a fix, and coordinate public disclosure after remediation is available. We will ask before publishing reporter attribution.