| Version | Supported |
|---|---|
| 0.3.x | Yes |
| < 0.3 | No |
Only the latest minor release receives security updates. We recommend always running the most recent version.
If you discover a security vulnerability in this project, please report it responsibly through GitHub's private security advisory feature.
Do not open a public issue for security vulnerabilities.
- Navigate to the Security tab of this repository
- Click "Report a vulnerability"
- Submit a Draft Security Advisory to the administrators of this project
- Provide as much detail as possible, including:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgement: Within 3 business days of your report
- Initial assessment: Within 7 business days
- Resolution timeline: Depends on severity; critical issues are prioritized
We will work with you to understand and address the issue before any public disclosure. We follow coordinated disclosure practices and will credit reporters (with permission) in release notes.
When contributing to this project, please:
- Never commit secrets, credentials, or API keys
- Follow the principle of least privilege in code changes
- Report any suspicious activity or potential vulnerabilities through the process above