| Version | Supported |
|---|---|
| 2.x | ✅ |
| 1.x (latest: v1.11.1) | |
| < 1.x | ❌ |
Do not open a public GitHub issue for security vulnerabilities.
Report vulnerabilities exclusively via GitHub Security Advisories (the "Report a vulnerability" button in the Security tab of this repository). This keeps details private until a fix is available (coordinated disclosure).
No email address is published for security reports — GitHub Advisories is the only channel.
| Milestone | Target |
|---|---|
| Acknowledge receipt | Within 3 days |
| Status update | Roughly every 2 weeks until resolved |
| Public disclosure | Coordinated with the reporter, after a patch is released — no fixed deadline |
We follow a coordinated-disclosure model: a fix is prepared and released before public disclosure. If you need a CVE, we will assist in requesting one via GitHub's advisory process.