| Version | Supported |
|---|---|
| latest release | Yes |
unreleased main |
Best effort |
| older releases | No |
Before the first release, reports against main are accepted. Afterward, security fixes target the most recent release.
Do not open a public GitHub issue for security vulnerabilities.
Use GitHub private vulnerability reporting (Security -> Advisories -> Report a vulnerability). If you are unsure whether something qualifies as a vulnerability, report it privately anyway.
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce or proof-of-concept code
- The version(s) affected
We will acknowledge the report within 3 business days and aim to release a fix within 14 days for critical issues. We will credit reporters in the release notes unless you prefer to remain anonymous.