Please report suspected vulnerabilities privately through GitHub private vulnerability reporting. Do not disclose a vulnerability in a public issue, pull request, discussion, or social-media post before a coordinated fix is available.
Include the affected component and revision, the expected impact, reproduction steps, and a minimal proof of concept where possible. Please avoid accessing, modifying, or deleting data beyond what is necessary to demonstrate the issue, and do not perform denial-of-service testing.
We aim to acknowledge a report within 48 hours, provide an initial assessment within seven days, and send status updates at least weekly while remediation is in progress. Disclosure timing will be coordinated with the reporter; the default target is within 90 days of the initial report.
Security fixes are made on the default branch. Tagged releases are supported only when explicitly identified as maintained in their release notes.
We will not pursue legal action against researchers who act in good faith, follow this policy, avoid privacy and service disruption, and allow reasonable time for remediation before disclosure.
The project's detailed security measures and cryptographic standards are documented in SECURITY.adoc.