We aim to support the latest tagged release and the main branch of this repository. Older tags may not receive security fixes.
Please report security issues privately via GitHub Security Advisories for this repository. Do not open a public issue for security findings.
Include:
- A short description of the issue and its impact
- Steps to reproduce (or a proof of concept if safe to share)
- Affected versions or revision, if known
We will acknowledge receipt as soon as we can and work with you on a coordinated disclosure when appropriate.
When this repository uses automated dependency update proposals, security fixes for dependencies are expected to land through that flow when upstream releases are available.