| Version | Supported |
|---|---|
| latest | ✅ |
| < 1.0 | ❌ |
Do not open a public issue for security vulnerabilities.
Use GitHub's private vulnerability reporting:
- Go to this repository's Security tab.
- Click Report a vulnerability.
- Fill in the advisory form.
If private vulnerability reporting is not enabled, contact the maintainers via the method documented in SUPPORT.md.
Include: description, steps to reproduce, potential impact, suggested fix.
| Action | Timeline |
|---|---|
| Acknowledgment | 48 hours |
| Initial assessment | 5 business days |
| Fix development | 14 business days |
| Public disclosure | After fix |
Security research conducted in good faith is authorized. We will not pursue legal action against researchers who act responsibly.