Please report security vulnerabilities using GitHub Security Advisories (private reporting).
- Do not open public issues for exploitable vulnerabilities.
- Include reproduction steps, impact, and affected components.
- Include a minimal proof of concept when possible.
- Report privately through GitHub Security Advisories.
- Maintainers triage and validate the issue.
- A fix is prepared and released.
- Public disclosure follows after a patch is available.
This project is maintained on a best-effort basis and does not provide SLA guarantees.