We take security issues seriously.
If you discover a vulnerability, please report it responsibly
Do NOT open a public issue for security vulnerabilities.
You can expect:
- A response within 48–72 hours
- Regular updates until resolution
- Credit (if desired) after fix is deployed
We appreciate responsible disclosure to keep the ecosystem safe.