Only actively maintained versions on the default branch are guaranteed to receive security fixes.
If you discover a security vulnerability, please do not disclose it publicly first.
Recommended process:
- Prepare a clear report:
- Affected version/commit
- Reproduction steps or PoC
- Impact assessment
- Contact maintainers through private channels if available.
- If private channels are unavailable, open a GitHub issue with minimal details and request private follow-up.
After confirmation and patch preparation:
- Maintainers coordinate a fix and release plan.
- Security notes are published with the release.
- Credits are provided when appropriate.