We actively support and provide security updates for the following versions:
| Version | Supported |
|---|---|
| Latest | ✅ |
| < Latest | ❌ |
We take security vulnerabilities seriously. If you discover a security vulnerability, please follow these steps:
- Do NOT create a public GitHub issue
- Email security details to: [Your Security Email] (or create a private security advisory)
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if available)
This project follows security best practices:
- ✅ Regular dependency updates via Dependabot
- ✅ Automated security scanning (CodeQL, npm audit, pip-audit)
- ✅ CI/CD pipeline with security checks
- ✅ Pinned dependencies where possible
- ✅ Regular security audits
- We will acknowledge receipt of your report within 48 hours
- We will provide an initial assessment within 7 days
- We will keep you informed of our progress
- We will notify you when the vulnerability is fixed
- We will credit you in the security advisory (if desired)
Security updates are released as soon as possible after a vulnerability is confirmed and fixed. Critical vulnerabilities may result in immediate patch releases.