This project publishes a versioned taxonomy rather than shipping application releases with parallel maintenance branches. Security and data-integrity fixes are applied to the latest published taxonomy version.
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
If you discover a security vulnerability, a data-integrity issue, or a supply-chain concern (for example in scripts/, CI workflows, or generated artifacts), please report it privately using GitHub's Security Advisories feature:
- Go to the repository's Security tab.
-
- Select "Report a vulnerability" to open a private advisory.
-
-
Include reproduction steps, affected files or paths, and potential impact.
-
Please do not open a public issue for suspected security problems.
-
You can expect an initial response within 5 business days. Confirmed issues will be tracked through a private advisory until a fix is published, at which point the advisory and a changelog entry will be made public. Declined reports will receive an explanation of why the issue was not accepted.
-
For non-security bugs, please use the standard issue templates instead.
-