Skip to content

Latest commit

 

History

History
34 lines (22 loc) · 1.02 KB

File metadata and controls

34 lines (22 loc) · 1.02 KB

Security Policy

Reporting a vulnerability

Do not open public issues for security findings.

Preferred channel:

  1. Go to Security -> Advisories -> Report a vulnerability in this repository.
  2. Provide impact, affected versions/commit, and reproduction steps.
  3. Include proof of concept and suggested mitigation when possible.

Direct link:

Response targets

  • Initial acknowledgment: within 72 hours.
  • Triage and severity classification: as soon as reproduction is confirmed.
  • Fix coordination: private until a patch is available.

Disclosure expectations

  • Use coordinated disclosure.
  • Do not publish exploit details before maintainers release a fix.
  • Test only on systems you own or have explicit written authorization to assess.

Supported versions

Only actively maintained branches/releases receive security fixes:

  • develop (active development)
  • main (stable release line)

Older snapshots and experimental branches may not receive patches.