If you discover a security vulnerability in this project, please report it responsibly.
Do NOT open a public GitHub issue.
Instead, report it privately through GitHub's private vulnerability reporting: Security > Report a vulnerability on this repository.
Please include, if possible:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested mitigation or fix (if known)
After receiving a report, the maintainers will:
- Acknowledge receipt of the report
- Investigate the issue
- Determine severity and impact
- Develop and release a fix if necessary
We aim to respond within 5 business days.
We ask that security researchers:
- Do not publicly disclose the vulnerability until a fix is available
- Allow reasonable time for investigation and remediation
- Avoid exploiting the vulnerability beyond what is necessary to demonstrate it
Security updates are generally provided for the most recent release. Older versions may not receive security patches.
When a vulnerability is fixed, updates are published through the repository's release process and documented in the release notes.