Security policy
July 28, 2026 ยท View on GitHub
Supported versions
| Version | Supported |
|---|---|
0.1.x | Yes |
0.1.0-rc.2 and older prereleases | No |
Reporting a vulnerability
Use GitHub private vulnerability reporting. Include:
- the affected version or Git commit;
- a minimal reproduction;
- the security impact;
- any known workaround.
Do not include credentials, proxy URLs, cookies, private search queries, or provider response bodies in a public issue.
If private vulnerability reporting is unavailable, open a public issue that asks for a private contact channel without disclosing the vulnerability.
The maintainers will acknowledge a valid report when review begins. No fixed
response-time promise applies to the 0.1.x line.
Scope
Useful reports include:
- proxy credential exposure;
- request cancellation or timeout bypass;
- server-side request forgery through proxy or URL handling;
- unbounded response processing;
- package or release integrity problems;
- provider response handling that exposes secrets.
DuckDuckGo availability, result ranking, bot challenges, and rate limits are
provider behavior unless they expose a security weakness in ddg-kit.