Security policy

July 28, 2026 ยท View on GitHub

Supported versions

VersionSupported
0.1.xYes
0.1.0-rc.2 and older prereleasesNo

Reporting a vulnerability

Use GitHub private vulnerability reporting. Include:

  • the affected version or Git commit;
  • a minimal reproduction;
  • the security impact;
  • any known workaround.

Do not include credentials, proxy URLs, cookies, private search queries, or provider response bodies in a public issue.

If private vulnerability reporting is unavailable, open a public issue that asks for a private contact channel without disclosing the vulnerability.

The maintainers will acknowledge a valid report when review begins. No fixed response-time promise applies to the 0.1.x line.

Scope

Useful reports include:

  • proxy credential exposure;
  • request cancellation or timeout bypass;
  • server-side request forgery through proxy or URL handling;
  • unbounded response processing;
  • package or release integrity problems;
  • provider response handling that exposes secrets.

DuckDuckGo availability, result ranking, bot challenges, and rate limits are provider behavior unless they expose a security weakness in ddg-kit.