1.3 KiB
1.3 KiB
Security Policy
Supported Versions
Security fixes are applied on a best-effort basis to the latest development state on main and the latest published package version.
Older releases may not receive fixes.
Reporting a Vulnerability
Please do not report security vulnerabilities in public GitHub issues or pull requests.
Instead, report them privately to [email protected]. If GitHub private vulnerability reporting is enabled for this repository, you may use the repository's "Report a vulnerability" flow instead.
Please include:
- A clear description of the issue
- Affected version or commit, if known
- Reproduction steps or a proof of concept
- Impact assessment, if you have one
- Suggested remediation, if available
What to Expect
- We will review reports as quickly as possible.
- We may ask follow-up questions to confirm impact and scope.
- We will aim for coordinated disclosure and a fix before public discussion.
- When appropriate, we will document the fix in a release note or security advisory.
Out of Scope
The following are usually not treated as security vulnerabilities by themselves:
- Requests for help with local environment setup
- Reports that only affect unsupported or heavily modified environments
- General dependency hygiene suggestions without a demonstrated impact on this project