If you discover a security vulnerability in this project, please report it responsibly:
- Do not open a public GitHub issue.
- Use GitHub's private vulnerability reporting (the "Security" tab → "Report a vulnerability"), or email the maintainer directly.
- Include a clear description of the vulnerability, steps to reproduce, and the potential impact.
We will acknowledge receipt within 48 hours and aim to provide a fix or mitigation within 14 days, depending on severity.
Only the latest release receives security updates.
Once a vulnerability is fixed and released, we will publish a GitHub Security Advisory crediting the reporter (unless they prefer to remain anonymous).