Skip to contents

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, report them privately to the project maintainer:

When possible, include:

  • a clear description of the issue
  • affected package version or commit
  • reproduction steps or a minimal example
  • any known impact or exploitation details

We will review reports as promptly as possible and coordinate any necessary fixes and disclosure.

Supported versions

Security fixes, when needed, are expected to target the latest development version and the most recent released package version.