Security fixes are provided for the latest patch release in the 0.1.x series.
Earlier releases, unreleased branches, and experimental interfaces are not supported.
| Version | Supported |
|---|---|
Latest 0.1.x release |
Yes |
| Earlier versions | No |
Do not report a suspected vulnerability in a public issue, discussion, or pull request.
Use GitHub's private vulnerability reporting:
- Open the repository's Security tab.
- Select Advisories.
- Select Report a vulnerability.
Include the affected version or commit, impact, prerequisites, reproduction steps, and any proposed mitigation. Remove credentials, proprietary model data, and unrelated production logs from the report.
The maintainers will confirm receipt, investigate the report, and coordinate remediation and disclosure with the reporter. Please allow the maintainers to publish a fix and advisory before public disclosure.
General usage questions and non-security defects belong in the public issue tracker.