Security fixes target the latest published release. Older builds may not receive patches.
Use GitHub Security Advisories for private reports. Do not open a public issue for an unpatched vulnerability.
Please include:
- affected ReadMD version and package type;
- operating system and architecture;
- minimal reproduction steps;
- impact you observed or believe is possible;
- safe logs without credentials or confidential paths.
There is no guaranteed response time. Reports are easier to evaluate when they avoid exploit payloads that expose private data and when they focus on the minimum steps needed to reproduce the issue.