Skip to content

Security Policy

Supported versions

Security fixes are provided for the latest released version. Always run the most recent release.

Version Supported
Latest release on main Yes
Older releases No

Reporting a vulnerability

Please do not open public issues for suspected vulnerabilities.

Report privately with as much detail as possible:

  • Affected component and version
  • Reproduction steps
  • Impact assessment
  • Suggested remediation (if known)

Preferred contact:

Please do not disclose the issue publicly until a fix is available.

Response targets

  • Initial acknowledgement: within 72 hours
  • Triage decision: within 7 calendar days
  • Remediation target: based on severity and exploitability

Sensitive data handling

  • Never include API keys, tokens, or private endpoint URLs in reports.
  • Sanitize logs before sharing.