| Version | Supported |
|---|---|
| 1.x | Yes |
| < 1.0 | No |
Please do NOT report security vulnerabilities through public GitHub issues.
Instead, use GitHub's private vulnerability reporting.
Please include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Initial response: within 48 hours
- Confirmation: within 5 business days
- Resolution: depends on severity and complexity
We follow coordinated disclosure:
- Reporter submits vulnerability privately
- We confirm and assess severity
- We develop and test a fix
- We release the fix and publish a security advisory
- Reporter may publish details after the fix is released