Do not open public issues for suspected vulnerabilities.
Report privately to project maintainers using GitHub private communication channels (for example, Security Advisories when enabled, or direct maintainer contact).
Include:
- affected version/commit
- reproduction steps
- impact assessment
- potential mitigation (if known)
- Initial triage target: 3 business days
- Status update target: 7 business days
- Fix and disclosure timeline depends on severity and exploitability
| Version | Supported |
|---|---|
| 0.1.x | Yes |
| < 0.1.0 | No |