Security updates are provided for the latest development version. Older releases may not receive fixes.
If you believe you have found a security vulnerability, please report it privately. Do not open a public issue or pull request.
Include as much information as possible:
- A description of the vulnerability.
- Steps to reproduce the issue.
- The affected version or commit.
- The expected and actual behavior.
- Any proof-of-concept code or screenshots, if applicable.
- Any suggested mitigation, if known.
After receiving a report, we aim to:
- Acknowledge receipt within a reasonable time.
- Investigate and reproduce the issue.
- Determine the severity and impact.
- Develop and test a fix.
- Coordinate disclosure with the reporter when appropriate.
- Publish a security advisory if necessary.
Please give us a reasonable amount of time to investigate and fix reported vulnerabilities before disclosing them publicly. Responsible disclosure helps protect users while a fix is being prepared.
Security fixes will be released as part of the normal development process. Users are encouraged to keep their installations up to date.
Thank you for helping improve the security of this project.