Until a stable release process is established, security fixes are targeted at the current main branch.
- Prefer a private reporting channel.
- If GitHub Security Advisories are enabled for the repository, use the "Report a vulnerability" flow.
- If no private reporting channel is available, contact the repository maintainers privately before public disclosure.
- Do not open a public issue for an unpatched vulnerability.
- A description of the affected component.
- Reproduction steps or a proof of concept.
- The impact and any known mitigations.
- The commit, branch, or version you tested.
The maintainers will aim to acknowledge reports promptly, validate impact, and coordinate remediation before public disclosure.