Security updates are applied to the latest 1.x release. Please update to the current version before reporting so we can confirm the issue on current code.
| Version | Supported |
|---|---|
| 1.14.x | ✅ |
| < 1.14 | ❌ |
Please do not open a public issue for security vulnerabilities. Public issues are visible to everyone and can expose users before a fix is available.
Instead, report privately through one of these channels:
- GitHub private vulnerability reporting (preferred). Go to the repository Security tab and choose Report a vulnerability. If this option is not visible, a maintainer can enable it under Settings > Security > Private vulnerability reporting.
- Direct contact. If private reporting is not enabled, open a short issue that asks for a private contact and shares no technical details, and a maintainer will follow up.
- A description of the vulnerability and its impact
- Steps to reproduce, or a proof of concept
- The affected version, endpoint, or file if known
- Any suggested fix (optional but appreciated)
- An acknowledgement of your report, typically within a few days
- An assessment of severity and a plan for a fix
- Coordinated disclosure: details are published after a fix is available, with credit to the reporter unless you prefer to remain anonymous
Thank you for helping keep this project and its users safe.