Security fixes currently target the latest 0.1.x release and the current default branch.
Report vulnerabilities privately through GitHub Security Advisories for this repository. Do not open a public issue for an unpatched vulnerability and do not include credentials, browser cookies, private media URLs, or downloaded content in a report.
Include:
- The affected version and platform.
- A minimal reproduction using non-sensitive test data.
- The expected and observed impact.
- Any mitigation you have already tested.
Expect an acknowledgement within seven days. Confirmed reports will be prioritized by exploitability and impact. Please allow time for a fix and release before public disclosure.
High-value areas include archive extraction, output-path handling, browser-cookie integration, dependency bootstrap, terminal disclosure, and untrusted extractor metadata. Source-platform availability problems without a security impact are regular bugs, not vulnerabilities.