Security updates are provided for the latest code on the main branch.
Please do not open public issues for security vulnerabilities.
Report privately with:
- Summary of the issue
- Reproduction steps
- Affected files or routes
- Impact assessment
Include logs or proof-of-concept details that help reproduce the issue safely.
Preferred reporting channels:
- GitHub private vulnerability reporting for this repository
- If private reporting is unavailable, contact the maintainer directly and share details privately
- Triage and confirm the report
- Prepare and test a fix
- Coordinate disclosure timing
- Publish the patch and update notes
- Please allow reasonable time for investigation and remediation before public disclosure
- Security fixes may be released without prior public discussion to protect users