If you discover a security vulnerability in this project, please report it privately.
- Do not open a public GitHub issue.
- Contact the maintainer directly via the repository's contact information (email or GitHub Security Advisories).
- Do not publicly disclose the vulnerability before a fix is available.
- A clear description of the vulnerability.
- Steps to reproduce the issue.
- The affected version(s), if known.
- Any potential impact assessment.
- Acknowledgment within 7 days.
- Assessment and triage within 14 days.
- A fix or mitigation will be prioritized based on severity.
Security fixes target the latest stable release line. Older releases may not receive updates.
This policy covers the library's core runtime code (src/). Example handlers, documentation, and build tooling are out of scope for security advisories.