Security fixes are made on the latest 1.x release line and the current default
branch. Older pre-1.0 releases are not maintained.
| Version | Supported |
|---|---|
| 1.x | Yes |
| < 1.0 | No |
Do not open a public issue for a suspected vulnerability. Use GitHub's private security advisory form so maintainers can investigate without exposing users before a fix is ready.
Please include the affected version or commit, reproduction steps, expected and observed behavior, security impact, and any suggested mitigation. Remove API keys, access tokens, personal data, and other secrets from the report.
Maintainers aim to acknowledge a report within three business days and provide an initial assessment within seven business days. Remediation and disclosure timing depend on severity, exploitability, and the availability of a safe fix.