We actively maintain the code in this repository. If you discover a security issue, please report it as outlined below.
Please DO NOT open a public issue for security vulnerabilities. Instead, contact the maintainers privately:
- Preferred: Open a private Discussion in the repository and mark it "security" (if Discussions is enabled).
- Alternative: Open a private issue and add the label
security(maintainers will convert it to a private channel if needed).
Include:
- A short description of the issue
- Steps to reproduce
- A minimal reproducible example (if applicable)
- A proposed mitigation
We will respond as soon as possible and coordinate a fix and disclosure plan.
Maintainers will triage reports via GitHub Discussions / Issues. If you need a direct contact, use the repository owner's public contact information on GitHub.
We aim to:
- Acknowledge receipt within 48 hours
- Provide a fix or mitigation plan within 14 days for high severity issues
Do not publicly disclose the vulnerability until a fix or mitigation has been published.