If you discover a security vulnerability in this project, please report it responsibly. We take all security issues seriously and appreciate your help in keeping this project safe for everyone.
Please do not open a public GitHub issue for security vulnerabilities. Instead, use GitHub's private vulnerability reporting feature:
- Go to the Security tab of this repository.
- Click Report a vulnerability.
- Fill out the form with as much detail as you can.
If private vulnerability reporting is not enabled on this repository, please reach out to a maintainer directly. You can find contact information in the project's README or contributor profiles.
When reporting a vulnerability, please provide:
- A clear description of the issue
- Steps to reproduce the behavior
- The potential impact or severity as you understand it
- Any suggested fixes, if you have them
- We will do our best to acknowledge your report in a timely manner.
- We will work with you to understand and validate the issue.
- We will keep you informed as we work on a fix.
- Once resolved, we will credit you in the release notes (unless you prefer to remain anonymous).
Please keep in mind this is a hobby project maintained in spare time, so response times may vary.
Security updates are applied to the latest release. If you are using an older version, we recommend upgrading to the most recent release to ensure you have all available fixes.
This policy applies to vulnerabilities found in this repository's code and its official releases. Third-party dependencies should be reported to their respective maintainers.
Thank you for helping us keep this project secure.