| Version | Supported |
|---|---|
| 1.1.x | ✅ |
| < 1.0 | ❌ |
If you discover a security vulnerability, please report it responsibly:
- Do not open a public GitHub issue
- Email security concerns to the maintainers via the repository contact
- Include steps to reproduce and potential impact assessment
- We aim to acknowledge reports within 48 hours
- All dependencies audited daily via
cargo-denyandcargo-audit unsafecode is forbidden project-wide (unsafe_code = "forbid")- BLAKE3 cryptographic hashing for all state integrity checks
- Supply chain security via pinned GitHub Actions SHAs and dependency allowlists