Security Policy

August 6, 2026 ยท View on GitHub

Supported versions

Security fixes are applied to the latest published 1.x minor release. Pre-1.0 (0.x) releases are no longer maintained.

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability. Use GitHub's Security โ†’ Report a vulnerability private reporting flow for this repository. Include affected versions, reproduction steps, impact and any suggested mitigation.

Reports will be acknowledged within seven days. Confirmed issues will receive a coordinated fix and advisory before public technical details are discussed.