Security fixes are applied to the latest code on main and, where applicable,
the latest published package versions. Pre-release and older package versions
may require upgrading to receive a fix.
Report suspected vulnerabilities through GitHub private vulnerability reporting. This creates a private security advisory that only repository maintainers and invited collaborators can access.
Do not open a public issue, discussion, or pull request for an undisclosed vulnerability.
Include:
- the affected component and version or commit
- the security impact and expected attack scenario
- clear reproduction steps or a minimal proof of concept
- any conditions required to exploit the issue
- a suggested mitigation, if you have one
Maintainers will acknowledge the report through the private advisory, assess its impact, and coordinate remediation and disclosure there.
When investigating a potential issue:
- use local environments or accounts and data you control
- avoid privacy violations, service disruption, denial of service, and data destruction
- do not access, retain, or disclose another party's secrets or data
- stop testing and report the issue if you encounter sensitive information
- give maintainers a reasonable opportunity to remediate before disclosure
Good faith research that follows this policy will be treated as authorized security research.