| Version | Supported |
|---|---|
| latest | Yes |
Please do not report security vulnerabilities through public GitHub issues.
Report vulnerabilities privately by emailing andre.vanklaveren@owasp.org.
Include as much detail as possible:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested mitigations
You can expect an acknowledgement within 48 hours and a status update within 7 days.
Once a fix is available we will:
- Release a patched version
- Publish a GitHub Security Advisory
- Credit the reporter (unless anonymity is requested)