If you believe you have found a security vulnerability, please do not open a public issue. Instead, contact the maintainer privately by either:
- Opening a private security advisory on GitHub (preferred), or
- Emailing the maintainer through their GitHub profile contact.
You can expect:
- An acknowledgment within 7 days
- An initial assessment within 14 days
- A fix or detailed mitigation plan within 30 days for high/critical severity issues
The latest tagged release is supported. Older versions receive only documented security backports if explicitly listed in a release note.
In-scope:
- The code in this repository
- The default-mode runtime behavior
Out of scope:
- Third-party dependencies (please report upstream)
- Issues that require a malicious local user with shell access
- Social-engineering attacks on the user