Skip to content

Latest commit

 

History

History
23 lines (15 loc) · 846 Bytes

File metadata and controls

23 lines (15 loc) · 846 Bytes

Security Policy

Supported Versions

Until a stable release process is established, security fixes are targeted at the current main branch.

Reporting a Vulnerability

  • Prefer a private reporting channel.
  • If GitHub Security Advisories are enabled for the repository, use the "Report a vulnerability" flow.
  • If no private reporting channel is available, contact the repository maintainers privately before public disclosure.
  • Do not open a public issue for an unpatched vulnerability.

What to Include

  • A description of the affected component.
  • Reproduction steps or a proof of concept.
  • The impact and any known mitigations.
  • The commit, branch, or version you tested.

Response Expectations

The maintainers will aim to acknowledge reports promptly, validate impact, and coordinate remediation before public disclosure.