Security updates are published for the latest stable 1.1.x release line.
| Version | Supported |
|---|---|
| 1.1.x | Yes |
| < 1.1 | No |
Do not open a public GitHub issue or pull request for security reports.
Please use GitHub private vulnerability reporting.
Include enough detail to reproduce the issue: affected version, impact, and steps or a proof of concept when possible.
Reports are typically acknowledged within 48 hours. Confirmed issues are patched in the latest 1.1.x release, with a GitHub security advisory published when disclosure is appropriate.