Security fixes are prioritized for the latest released version and the current main branch.
Older versions may receive fixes when the impact is high and a backport is practical, but long-term support is not guaranteed by default.
Please privately report suspected vulnerabilities instead of opening a public issue.
Preferred reporting channels are:
- GitHub private vulnerability reporting or Security Advisories, when enabled for the repository;
- a maintainer contact channel documented by the project, when private GitHub reporting is not available.
Include enough detail to help maintainers reproduce and assess the issue:
- affected project version or commit;
- affected platform or runtime, when relevant;
- a minimal reproduction or proof of concept;
- expected impact and any known mitigations.
Maintainers should acknowledge and triage reports as soon as reasonably possible. Response and fix timelines depend on severity, maintainer availability, release complexity, and coordinated disclosure needs.
Sensitive details should remain private until a fix or mitigation is available, unless disclosure is legally required or already public.