The current 0.1.x line receives security fixes. Older snapshots are not maintained separately.
Use GitHub's private vulnerability reporting for this repository:
- Open the repository's Security tab.
- Choose Advisories.
- Select Report a vulnerability.
Do not open a public issue for a suspected vulnerability.
Describe the affected version, the conditions required to reproduce the problem, the likely impact, and any mitigation you have already tested. Remove credentials, usernames, absolute home-directory paths, live session contents, and unredacted logs before attaching evidence.
The maintainer will acknowledge the report, investigate it, and coordinate disclosure and a fix through the private advisory. This project does not promise a fixed response-time SLA.