Please read out Reporting security issues documentation. It hopefully covers everything you need to know.
Please do not open a public issue, pull request or discussion for a security problem.
A public report makes the issue known to everyone while all installations are still unpatched, so it puts users at risk before they can protect themselves.
Report it privately instead, using one of these:
- Report a vulnerability through GitHub. Only the maintainers can see it, and you can attach a suggested patch.
- Email us, you find the address here.
You can expect a first reply within a few days. Once a fixed release is available, the advisory is published and you are credited, unless you prefer not to be named.
Please check the latest release before reporting: the issue you found may already be fixed.
As announced in the README security fixes will only be added to the main branch.
| Version | Supported |
|---|---|
| main branch | ✅ |
| older releases | ❌ |
There are no backports to older releases. Updating to the current release is the only way to receive a security fix.