| Version | Supported |
|---|---|
| 5.1.x | ✅ |
| 5.0.x | ❌ |
| 4.0.x | ✅ |
| < 4.0 | ❌ |
We take security issues seriously and appreciate your efforts to responsibly disclose vulnerabilities.
- Where to report: Please submit security issues via GitHub Security Advisories.
- Response time: You can expect an initial response within 72 hours. We will provide regular updates (at least once a week) until the issue is resolved.
- What to include:
- A clear description of the vulnerability
- Steps to reproduce the issue
- Potential impact if exploited
- Suggested mitigation (if available)
- If the vulnerability is accepted, we will:
- Work on a fix promptly.
- Credit you in the release notes (unless you prefer anonymity).
- Provide a patched release as soon as possible.
- If the vulnerability is declined (e.g., not reproducible or out of scope), we will explain the reasoning clearly.