Security Policy¶
Supported versions¶
Security fixes are provided for the latest released version. Always run the most recent release.
| Version | Supported |
|---|---|
Latest release on main |
Yes |
| Older releases | No |
Reporting a vulnerability¶
Please do not open public issues for suspected vulnerabilities.
Report privately with as much detail as possible:
- Affected component and version
- Reproduction steps
- Impact assessment
- Suggested remediation (if known)
Preferred contact:
- Open a private GitHub security advisory for this repository.
Please do not disclose the issue publicly until a fix is available.
Response targets¶
- Initial acknowledgement: within 72 hours
- Triage decision: within 7 calendar days
- Remediation target: based on severity and exploitability
Sensitive data handling¶
- Never include API keys, tokens, or private endpoint URLs in reports.
- Sanitize logs before sharing.