Only the latest release and the current main branch receive security
updates.
| Version | Supported |
|---|---|
| v0.3.x | ✅ Current release |
| < v0.3 | ❌ Unsupported |
Please do not disclose security vulnerabilities through public GitHub Issues — that gives attackers a head start before a fix is available.
To report a vulnerability privately, use the repository's private reporting mechanism if it is enabled (GitHub's Security tab → "Report a vulnerability"), or contact the repository maintainer directly through a private channel.
If neither private reporting nor a maintainer contact channel is available, please open a minimal public issue without exploit details and ask the maintainer to move the discussion to a private channel.
When reporting, please include as much of the following as possible:
- Affected version(s)
- A description of the vulnerability and its impact
- Steps to reproduce (or a minimal proof of concept)
- Any relevant configuration or environment details
- Do not create a public issue with full exploit details
- Do not demand a public disclosure timeline
- Do not exfiltrate data while testing a vulnerability