Security fixes are applied to the latest release and to main while the next
release is in development. Older releases may be asked to upgrade before a fix
is provided.
Do not open a public issue for a suspected vulnerability.
Use Security → Report a vulnerability in this GitHub repository. Include:
- the affected version or commit;
- the operating system and installation method;
- clear reproduction steps and impact;
- any suggested mitigation; and
- only the minimum logs or sample data needed to investigate.
Remove credentials, private files, and personal data from reports. The maintainers aim to acknowledge a report within three business days and will coordinate remediation and disclosure with the reporter.
For a private Code of Conduct report, use the same channel and prefix the title
with [Conduct].