Maintainers have not published a supported-version matrix. Before relying on this policy for a particular release series, confirm the supported version with the maintainers. The latest release is the appropriate starting point for a security report.
Please do not report security vulnerabilities in public issues. Use this repository's private vulnerability reporting channel:
- Open the repository's Security tab.
- Select Report a vulnerability.
- Include affected versions, reproduction steps or proof of concept, impact, and any proposed mitigation.
If the report concerns an exposed secret, revoke or rotate it immediately and state that rotation in the private report without including the secret value.
The project does not currently publish response-time service-level objectives. Maintainers should acknowledge private reports, assess impact and affected versions, coordinate a fix, and provide status updates through the private report. Please allow time for a fix before public disclosure.