Security fixes are provided for the latest release on the main branch.
| Version | Supported |
|---|---|
| Latest release | Yes |
| Older releases | No |
Please do not report security vulnerabilities through public GitHub issues.
Use GitHub Security Advisories to send a private report.
Please include:
- A description of the vulnerability
- The affected version or commit
- Reproduction steps or a proof of concept
- The expected and actual behavior
- Relevant logs, traces, or configuration
- The potential security impact
Please avoid including real secrets, credentials, or private user data in the report.
We will acknowledge valid reports, investigate their impact, and coordinate disclosure of fixes with the reporter.
Public disclosure should wait until a fix or mitigation is available.