Security fixes are provided for the latest release on main.
- Use GitHub private vulnerability reporting for this repository.
- Include:
- affected component/file
- reproduction steps
- impact assessment
- suggested mitigation if available
Do not open public issues for unpatched vulnerabilities.
- Initial triage response: within 5 business days.
- Confirmed vulnerability status update: within 10 business days.
- Fix timeline depends on severity and complexity; maintainers will communicate milestones in the private thread.