Security fixes are provided for the latest released minor version. Older versions may receive fixes only when practical.
Do not open a public issue for a suspected vulnerability.
Use GitHub's Report a vulnerability feature under the repository Security tab. Include:
- affected version or commit;
- operating system and shell version;
- reproduction steps;
- impact and affected trust boundary;
- suggested mitigation, when known.
Do not include real credentials, private repository data, or harmful payloads beyond what is required to demonstrate the issue.
- acknowledgement: within 7 days;
- initial assessment: within 14 days;
- remediation timing: based on severity and release risk.
These are targets, not a service-level agreement.