Only the latest version on the main branch is actively supported with security updates.
If you are running an older version, please update before reporting issues.
If you discover a security vulnerability, please report it responsibly.
Do NOT open a public GitHub issue.
Instead, report it privately using one of the following:
When reporting, please include:
We aim to:
Please allow reasonable time for the vulnerability to be fixed before any public disclosure. Responsible disclosure helps keep users and contributors safe.
This policy applies to:
Third-party dependencies should be reported to their respective maintainers unless the issue is caused by integration in this project.
Thank you for helping keep this project secure.