Security Policy

July 12, 2026 ยท View on GitHub

Supported versions

Security updates are applied to the latest published versions of each SDK in this repository. If you are on an older release, upgrade to the latest version of the affected package before reporting a regression.

Reporting a vulnerability

Do not open a public GitHub issue for security vulnerabilities.

This repository has GitHub Private Vulnerability Reporting enabled.

  1. Go to the Security tab of this repository.
  2. Choose Report a vulnerability.
  3. Include as much detail as you can: affected package and version, environment, reproduction steps, and impact.

We will acknowledge reports and work with you on a coordinated disclosure when a fix is available.

Prefer not to use GitHub?

If private reporting is unavailable for your account, contact the maintainers through your existing Toggly support channel and ask to be connected for a security report. Do not include exploit details in public issues, pull requests, or discussions.