Until a stable release process is established, security fixes are targeted at the current main branch.
Use GitHub's private vulnerability reporting flow for this repository:
If private reporting is not available to you, contact the project maintainers privately through GitHub and request a secure channel before sharing sensitive details.
Do not open a public issue for an unpatched vulnerability.
- A description of the affected component.
- Reproduction steps or a proof of concept.
- The impact and any known mitigations.
- The commit, branch, or version you tested.
The maintainers will aim to acknowledge reports promptly, validate impact, and coordinate remediation before public disclosure.