This project is pre-1.0. The latest commit on main is the only supported line. There are no backport or LTS branches.
| Version | Supported |
|---|---|
main (latest) |
Yes |
| Older commits | No |
Please do not file public GitHub issues for security vulnerabilities.
Use GitHub's private vulnerability reporting to disclose findings confidentially:
This creates a private advisory visible only to the maintainer and any collaborators you add.
The maintainer will acknowledge receipt within 7 days, best-effort. There is no formal SLA pre-1.0. Complex vulnerabilities may take longer to assess and patch.
This project follows coordinated disclosure:
- Reporter submits a private report.
- Maintainer acknowledges within 7 days and assesses severity.
- Maintainer develops and tests a fix privately.
- Maintainer and reporter agree on a disclosure date (typically 30–90 days from report, or sooner if a fix is ready).
- Fix is published; a public advisory is issued simultaneously.
If the maintainer does not respond within 14 days, the reporter may proceed with public disclosure at their discretion.