Security Policy

February 9, 2026 ยท View on GitHub

Supported Versions

Security fixes are applied to:

  • main branch
  • The latest tagged release

Older releases may not receive security updates.

Reporting a Vulnerability

Please do not open public issues for security reports.

Use one of these private channels:

  1. GitHub Security Advisories private reporting ("Report a vulnerability" in the repository Security tab), if enabled.
  2. Direct private contact to the repository owner via GitHub profile message.

Include:

  • A clear description of the issue
  • Reproduction steps and impact
  • Affected versions/commit
  • Any suggested mitigation

Response Expectations

  • Initial acknowledgment target: within 5 business days
  • Status updates: at least every 7 business days while triaging
  • Fix timeline depends on severity and release constraints

Disclosure

Please allow time for a fix before public disclosure. Once fixed, maintainers will coordinate disclosure details and release notes.