Security is a top priority for this project. If you discover a vulnerability, please report it immediately so steps can be taken to address it.
Please do not report security vulnerabilities through public GitHub issues.
Instead, please report them directly by opening a new Security Advisory
- A descriptive summary of the vulnerability.
- The steps to reproduce the issue (including any relevant configuration files, OS details, or environment setup).
- Any proof-of-concept (PoC) code or scripts.
- The potential impact of the vulnerability.
You should receive an initial triage response within 48 hours. You will be kept informed of the progress towards a fix and the timeline for a patch release.
If you prefer to encrypt your vulnerability report, please indicate this in your initial contact to receive the appropriate PGP public key for secure transmission.