We provide best-effort security fixes for the latest released version and the main branch.
| Version | Supported |
|---|---|
| Latest release | Yes |
main branch |
Yes |
| Older releases | No |
Please do not open public issues for suspected security vulnerabilities.
Use one of these private channels:
- GitHub Security Advisory (preferred): repository
Securitytab ->Report a vulnerability - If advisory is unavailable, contact maintainers through private channels listed in repository settings.
- Initial acknowledgement: within 72 hours
- Triage decision: within 7 days
- Status updates: at least every 7 days until resolution
- We coordinate a fix before public disclosure.
- Once fixed, we publish release notes with mitigation guidance.
- If secret leakage is involved, keys/tokens must be rotated immediately.