Security fixes are expected for the latest published release line.
| Version | Supported |
|---|---|
0.1.x |
Yes |
< 0.1.0 |
No |
Please do not report security vulnerabilities through public GitHub issues.
Preferred process:
- Use GitHub private vulnerability reporting:
Security->Advisories->Report a vulnerability. - If private vulnerability reporting has not been enabled yet, open a minimal public GitHub issue that requests a private security contact path without including exploit details, secrets, payloads, or full reproduction steps.
- Include a clear description of impact, affected versions, reproduction details, and any known mitigations once a private channel is established.
- Initial acknowledgement: within 3 business days
- Status update after triage: within 7 business days
- Fix timeline: depends on severity, exploitability, and release complexity
- Please allow time for investigation and coordinated remediation before public disclosure.
- Credit for responsible disclosure will be given unless you request otherwise.