Security fixes are applied to the latest stable release branch.
Please do not disclose vulnerabilities publicly before a fix is available.
- Open a private security report if available on the repository host.
- If private reporting is not available, contact maintainers directly.
- Include reproduction steps, impact, and affected version.
- Initial acknowledgement: within 72 hours.
- Triage and severity assessment: as soon as possible.
- Fix and disclosure timeline: depends on severity and exploitability.
When reporting, include whether the issue affects:
- Credential handling and secret exposure.
- Outreach safety defaults or anti-abuse behavior.
- Dependency or supply-chain risks.
- Data persistence in logs/database/exports.