Security fixes are provided for the latest code on the main branch.
Please do not open public issues for suspected vulnerabilities.
Instead, report privately by contacting the maintainers with:
- A clear description of the issue
- Affected package(s) and version/commit
- Reproduction steps or proof-of-concept
- Impact assessment (what can an attacker do)
- Suggested mitigation, if available
If GitHub Security Advisories are enabled for this repository, prefer using private vulnerability reporting there.
Target timeline:
- Acknowledgement: within 3 business days
- Initial triage: within 7 business days
- Remediation plan or workaround: within 14 business days
These are targets and may vary based on severity and complexity.
Please allow maintainers time to investigate and release a fix before public disclosure.