Do not report security vulnerabilities through public GitHub issues.
Report vulnerabilities privately using GitHub private vulnerability reporting. Please include:
- A description of the vulnerability and its potential impact
- The affected version or commit
- Steps to reproduce or a proof of concept
- Any known mitigations or suggested fixes
This project is experimental. Security fixes are generally applied to the latest development version. If supported releases are introduced, their support status will be documented here.
Please allow the maintainers an opportunity to investigate and prepare a fix or mitigation before publicly disclosing a vulnerability. The maintainers will coordinate disclosure with the reporter through the private advisory.