Please report security vulnerabilities privately by opening a GitHub security advisory or contacting the maintainers through the repository's preferred private security channel.
Do not include API keys, personal data, screenshots of sensitive screens, or exploit details in public issues.
- The maintainers acknowledge the report.
- The issue is reproduced and assessed.
- A fix is prepared and reviewed.
- A release or patch guidance is published.
- Credit is given when requested and appropriate.
Security fixes target the latest version on the default branch unless the project documents maintained release branches.