We release security updates for the following versions:
| Version | Supported |
|---|---|
| Latest | ✅ |
| < Latest | ❌ |
We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.
- Buffer overflows or memory safety issues
- SQL injection or command injection vulnerabilities
- Authentication or authorization bypasses
- Denial of service vulnerabilities
- Information disclosure vulnerabilities
- Any other security-related issue
DO NOT open a public GitHub issue for security vulnerabilities.
Instead, please report via:
- GitHub Security Advisories (preferred): Use the "Security" tab in the repository to report a vulnerability privately
- Email: Send details to the maintainers at their GitHub profile email addresses
When reporting a vulnerability, please include:
- Description of the vulnerability
- Steps to reproduce or proof of concept
- Potential impact
- Suggested fix (if you have one)
- Your contact information for follow-up
- Initial response: Within 48 hours
- Status update: Within 7 days
- Resolution target: Within 30 days (depending on severity and complexity)
- We will work with you to understand and validate the issue
- We will develop and test a fix
- We will release the fix and coordinate disclosure
- We will credit reporters (unless they prefer to remain anonymous)
We consider security research conducted in accordance with this policy to be "authorized" conduct under the Computer Fraud and Abuse Act. We will not pursue legal action against researchers who:
- Act in good faith
- Avoid privacy violations and data destruction
- Don't degrade the quality of the service
- Report vulnerabilities promptly
When using this project:
- Keep dependencies up to date
- Use the latest stable release
- Follow the principle of least privilege
- Validate all inputs
- Use secure configuration settings
- Monitor for security advisories
Security updates are announced via:
- GitHub Security Advisories
- Release notes
- GitHub repository notifications
Subscribe to repository notifications to receive security update announcements.
For security-related questions, please use the reporting channels above rather than public issues or discussions.