Security fixes are assessed for the latest released version of gly and the current master branch. Older releases are not supported.
Please do not report security vulnerabilities in public issues, discussions, or pull requests.
Use GitHub private vulnerability reporting to submit a confidential report. If that is unavailable, email prsroman3@gmail.com with the subject gly security report.
Include a clear description of the issue, affected version or commit, reproducible steps or proof of concept, impact assessment, and any suggested mitigation. Do not include secrets or sensitive personal data.
The maintainer will acknowledge receipt, investigate the report, and coordinate a fix and disclosure where appropriate.