Use this section to tell people about which versions of your project are currently being supported with security updates.
| Version | Supported |
|---|---|
| 5.1.x | ✅ |
| 5.0.x | ❌ |
| 4.0.x | ✅ |
| < 4.0 | ❌ |
To report a security vulnerability, please contact our security team at security@example.com or use the private "Report a vulnerability" feature on our GitHub repository if available.
We aim to acknowledge all vulnerability reports within 3 business days. You can expect follow‑up updates at least once every 7 business days while we investigate and work on a fix.
After receiving your report, we will:
- Confirm receipt and request any additional information we need.
- Triage and assess the impact and severity of the issue.
- Develop, test, and prepare a fix and any necessary mitigations.
- Coordinate a disclosure timeline with you, including when a fix will be released and when the issue can be publicly disclosed.
If we determine that the reported issue is not a security vulnerability or is out of scope, we will explain our reasoning. In all cases, we strive to keep you informed throughout the process.