Until version 1.0, only the latest release receives security fixes.
Please use GitHub private vulnerability reporting for this repository. Do not open a public issue containing a working exploit, credential, or undisclosed vulnerability in another project.
Include:
- affected version or commit;
- minimal reproduction;
- expected and observed behavior;
- impact and required attacker access;
- whether another project must be notified before publication.
The maintainer will acknowledge a complete report within seven days and provide a status update at least every fourteen days until resolution.
Follow the affected project's security policy. Share the smallest useful reproduction and allow maintainers time to fix before publishing details.