The project currently provides security updates for the following version line:
| Version | Supported |
|---|---|
| 5.1.x | ✅ |
| 5.0.x | ❌ |
| < 5.0 | ❌ |
Please report vulnerabilities privately.
Preferred channel:
- Use GitHub Security Advisories (Repository -> Security -> Report a vulnerability).
Fallback if Security Advisories are unavailable:
- Open a GitHub issue with title prefix
[SECURITY]and include minimal details. - A maintainer will move discussion to a private channel.
- Affected version and environment
- Reproduction steps
- Security impact
- Suggested fix or mitigation (optional)
- Initial acknowledgement: within 72 hours
- Follow-up updates: at least once every 7 days until resolution
- Do not publish exploit details before a patch or mitigation is available.
- Coordinated disclosure is preferred.