We take security seriously. If you discover a security vulnerability, please report it privately — do not open a public issue.
Preferred: GitHub private vulnerability disclosure — use the "Report a vulnerability" button on the repo's Security tab. This routes the report straight to the maintainer.
| Timeframe | Expectation |
|---|---|
| 48 hours | Acknowledgment of the report |
| 1 week | Initial assessment + triage status |
| Ongoing | Progress updates until resolution |
Issues in the source code, build pipeline, or dependencies of this project. For vulnerabilities in upstream dependencies, please report to the upstream maintainers instead.
- Include steps to reproduce, affected versions, and any suggested fix.
- Do not exploit the issue beyond demonstrating it.
- We appreciate coordinated disclosure and credit researchers who report responsibly.