Please do not open a public GitHub issue for security vulnerabilities.
Use GitHub's private vulnerability reporting instead:
GitHub Security Advisories allow you to describe the issue privately. The maintainer will acknowledge receipt and work with you on a fix before any public disclosure.
| Version | Supported |
|---|---|
| 1.0.x | Yes |
| < 1.0 | No |
| Stage | Target |
|---|---|
| Initial acknowledgement | Within 7 calendar days of receipt |
| Resolution (critical severity) | Within 30 calendar days of initial report |
This project follows a coordinated disclosure model with a 90-day window from the date of the initial private report. After 90 days (or sooner, once a fix is released and users have had time to update), the issue may be disclosed publicly regardless of patch status. We will notify you before any public disclosure.
If you have a strong reason to request an extension or an accelerated timeline, please say so in your advisory report.