Security fixes are prepared for the latest released minor version.
Before 1.0.0, security fixes target the current master branch and are
included in the next release.
Do not open a public issue for a vulnerability.
Use GitHub private vulnerability reporting for this repository. Include:
- affected VersionInfo.swift version or commit
- Swift version and platform
- whether the issue affects the plugin, the generator, the library, or generated source
- a minimal reproduction
- impact and exploitability notes
- whether the issue is already public
The maintainer will triage the report, ask for clarification when needed, and coordinate a fix before public disclosure.
Security reports that are not vulnerabilities may be moved to normal issues after removing sensitive details.