| Version | Security support |
|---|---|
| 0.3.x | Supported |
| 0.2.x and earlier | Upgrade required |
Use GitHub's Report a vulnerability form in the repository Security tab. This creates a private security advisory visible to the maintainer and avoids publishing exploit details in an issue, discussion, or pull request.
Include the affected version, macOS version and architecture, authorization mode, reproduction steps, expected/observed behavior, and the security impact. Do not include administrator passwords, private keys, access tokens, or other unrelated secrets.
Reports will be evaluated against the boundaries in
docs/security.md. Public disclosure should wait until a
fix or coordinated advisory is available.