We take the security of this project seriously. If you believe you have found a security vulnerability, please report it to us responsibly using the instructions below.
Only the latest tagged release and active development branch main receive security updates.
⚠️ Do NOT open public GitHub issues, discussions, or pull requests for security vulnerabilities.
Please submit reports directly via GitHub Private Vulnerability Reporting:
- Go to the repository's Security tab
- In the left sidebar, click Reporting
- Click Report a vulnerability to open the advisory form
To help us triage and resolve the issue quickly, please include:
- Description: A brief summary of the type of vulnerability (e.g., injection, privilege escalation)
- Location: Affected files, functions, or dependencies
- Reproduction Steps: Step-by-step instructions or proof-of-concept code
- Impact: What an attacker could achieve if the issue is exploited
- Acknowledgment: We will acknowledge receipt of your report within 72 hours
- Investigation: We will evaluate the report and communicate progress via the private GitHub Advisory thread
- Fix & Release: Once a fix is verified, we will issue an update and coordinate a public Security Advisory, crediting your contribution if desired