- Security SLA: We do not provide a security SLA for community users. Users are encouraged to review the code and report any vulnerabilities they find.
- Release schedule: Releases prioritize new features and include fixes for known security vulnerabilities at release time. However, there is no guarantee that all vulnerabilities will be fixed in every release.
- Version support: We may provide the project's latest version, but we do not guarantee support for older versions. Users are encouraged to upgrade to the newest version to benefit from security fixes.
If you discover a security vulnerability within this project, please report it privately using GitHub's private vulnerability reporting form, rather than a public issue or pull request. This gives us a private channel to confirm the issue and prepare a fix before any details become public.
As noted above, we do not provide a security SLA for community users, so please don't expect a guaranteed response time — but your report will be reviewed.
Your contributions to improving the security of this project are greatly appreciated.