| Version | Supported |
|---|---|
| latest | ✅ |
We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.
- Do NOT open a public GitHub issue for security vulnerabilities
- Use GitHub private vulnerability reporting if enabled, or contact the maintainer through the repository owner profile
- Include detailed steps to reproduce the vulnerability
- Manual review required: a dedicated response-time policy has not been published yet
- Type of vulnerability
- Full paths of affected source files
- Location of the affected source code (tag/branch/commit or direct URL)
- Step-by-step instructions to reproduce
- Proof-of-concept or exploit code (if possible)
- Impact of the issue
- Acknowledgment timing depends on maintainer availability until a dedicated security contact is published
- Regular updates on our progress
- Credit in the security advisory (if desired)
- Notification when the issue is fixed
When contributing to this project:
- Never commit secrets, API keys, or credentials
- Use environment variables for sensitive configuration
- Follow secure coding practices
- Report any security concerns immediately
Manual review: add a dedicated security email or enable GitHub private vulnerability reporting before accepting broad outside security reports.