Until the first stable release, security fixes are made on the latest development line only.
Do not open a public issue for a suspected vulnerability. Send a private report to
security@vkui.dev with the affected revision, platform, reproduction steps, impact, and any
suggested mitigation. Do not include secrets or personal data that are not necessary to reproduce
the problem.
The maintainers aim to acknowledge a report within seven days, validate it, coordinate a fix and release, and credit the reporter if requested. This document describes a project process and does not promise a particular response or remediation deadline.