Please report security vulnerabilities privately — do not open a public issue or pull request for a suspected vulnerability.
Use GitHub's private vulnerability reporting for this repository: Report a vulnerability.
Please include enough detail to reproduce: affected crate/version, a description of the issue and its impact, and a proof of concept or steps to reproduce where possible.
- We aim to acknowledge a report within a few business days.
- We will keep you informed as we investigate and work on a fix.
- Once a fix is released, we will publish a security advisory and credit the reporter unless you prefer to remain anonymous.
The project is pre-1.0 and under active development. Security fixes are made
against the latest released version on the main branch; please upgrade to the
latest release before reporting.