Security fixes are most likely to land in the latest release line or beta line.
Current priority:
0.11.0-alpha.2pre-release builds
Older 0.10.0 alpha builds and every 0.9.x or earlier line may receive no
fixes. Upgrade to the newest published build before reporting a vulnerability
unless the issue prevents upgrading or also reproduces there.
Please do not post exploit details in a public issue.
If GitHub private vulnerability reporting is available for this repository, use that first.
If private reporting is not available, open a minimal public issue without sensitive details and clearly state that the report is security-sensitive.
Please include:
- affected version
- what component is involved
- what the impact appears to be
- whether the issue requires a crafted archive, file, path, or configuration
Normal crashes, preview failures, or DDS compatibility bugs that are not security-sensitive should go through the normal issue tracker instead.