Please report a security vulnerability directly to the maintainers by contacting:
Include the following details in your message:
- Description of the vulnerable component and the potential impact.
- Steps to reproduce the vulnerability and a minimal proof-of-concept (if possible).
- Any patches or mitigation steps you can suggest.
If you would rather not disclose the vulnerability publicly, please use the email above and mark the report as a security disclosure. The maintainer team will follow up with you as soon as possible.
Security fixes are only addressed for the currently maintained versions. If you are using an outdated major release, please update to the latest supported release.
- We will acknowledge each vulnerability report within 48 hours.
- We will work to provide fixes or mitigation, and coordinate disclosure with the reporter.
- For urgent and critical security issues, please use the Security Policy and reach out to the maintainers via the email above. We will escalate as needed.