Security fixes are provided for the latest release line.
| Version | Supported |
|---|---|
| 0.4.x | Yes |
| 0.3.x | Security fixes only |
| < 0.3 | No |
Do not open a public issue for an undisclosed vulnerability. Submit a private GitHub security advisory with:
- The affected version and platform.
- Reproduction steps or a minimal proof of concept.
- The expected and observed behavior.
- The likely impact and any known mitigations.
Do not include real credentials, private keys, customer scan results, or data from systems you do not own or have permission to test.
Maintainers will acknowledge the report, validate its scope, coordinate a fix and release, and agree on a disclosure date with the reporter. Public disclosure should wait until a fix is available or the coordinated date is reached.
Good-faith research that avoids privacy violations, service disruption, data destruction, and access beyond what is necessary to demonstrate the issue is welcome. This policy does not authorize testing third-party systems.