valiss is pre-1.0. Security fixes land on the latest minor of the latest release line only; older lines are not maintained. Upgrade to the newest release before reporting, and expect fixes to ship forward rather than as backports.
Report suspected vulnerabilities privately. Please do not open a public issue for a security problem.
Use GitHub's private vulnerability reporting for this repository: open the Security tab and choose Report a vulnerability. This routes the report privately to the maintainer.
valiss is maintained by a single maintainer on a best-effort basis, with no service-level agreement on response or fix time. Coordinated disclosure is preferred: please allow a reasonable window to release a fix before any public disclosure.