Only the latest default branch is supported for security updates.
Do not open public issues for security vulnerabilities.
Please use GitHub Security Advisories to privately disclose vulnerabilities. If advisories are not available, contact the maintainers through a private channel and include:
- A clear description of the issue
- Impact and affected components
- Reproduction steps or proof of concept
- Suggested remediation if available
- We acknowledge reports within 3 business days.
- We triage and confirm severity.
- We prepare and test a fix.
- We publish a coordinated disclosure with remediation guidance.
Security reports should focus on exploitable vulnerabilities, including but not limited to authentication bypass, data exposure, injection flaws, privilege escalation, and insecure dependency usage.