Security fixes are provided for the latest stable release. A fix may first be published as a beta when validation against live or replay timing data is required.
Use GitHub's private vulnerability reporting for this repository. Do not include Formula 1 account credentials, access tokens, Home Assistant URLs, precise location data, or diagnostic archives in a public issue.
Include the affected version, the observable impact, and the smallest safe reproduction you can provide. Maintainers aim to acknowledge a report within 72 hours and provide a status update within seven days. Public disclosure should wait until a fix or an agreed mitigation is available.
Critical runtime vulnerabilities are assessed within 48 hours and targeted for remediation within seven days. High-severity runtime vulnerabilities are assessed within seven days and targeted for remediation within 30 days. Build-only findings without an upstream fix must be documented in the expiring audit allowlist and re-reviewed before expiry.