Security fixes are provided for the latest 0.x release only.
Do not open a public issue for a suspected vulnerability. Report it through GitHub private vulnerability reporting.
Include, when available:
- the affected nshell version;
- steps or a minimal example that reproduce the issue;
- the security impact; and
- any known mitigation or workaround.
After receiving a report, maintainers will acknowledge and triage it. The time needed to investigate and release a fix depends on the issue, so this policy does not guarantee a remediation deadline.
We ask reporters to follow good-faith coordinated disclosure: keep details private while the issue is investigated and coordinate public disclosure with the maintainers.