Only the latest released version receives security fixes.
| Version | Supported |
|---|---|
| latest | yes |
| older | no |
Do not open a public issue or Discussion for a security vulnerability.
Use GitHub's private vulnerability reporting from the Security tab of this repository (the "Report a vulnerability" button). This keeps the report confidential until a fix is ready.
Include the following in your report:
- Vulnerability description and impact — what it is and what an attacker could do.
- Reproduction steps or proof of concept — enough detail to reproduce the issue.
- Affected version(s) — which release(s) are affected.
Response: you can expect an initial response within a few days. Once a fix is ready, a new release will be published and the advisory will be disclosed.