Please do not open a public GitHub issue for security vulnerabilities.
Instead, use GitHub's private security advisory feature:
- Go to Security > Advisories
- Click "New draft security advisory"
- Describe the vulnerability with steps to reproduce
- The maintainer will be notified privately and can work with you on a fix
You can also email a detailed report to matt82198@gmail.com if you prefer.
Only the latest 0.3.x release receives security updates.
| Version | Status | Support ends |
|---|---|---|
| 0.3.x | Actively supported | TBD |
| < 0.3 | Not supported | — |
- Security patches will be released as soon as possible after confirmation
- Public disclosure will occur after a patch is released
- If a vulnerability is already public, we will prioritize a fix over coordinated disclosure