Security fixes are currently provided for the latest code on the main branch.
Please do not create a public GitHub issue for security vulnerabilities.
Preferred reporting channel:
- GitHub Security Advisories:
Securitytab in this repository ->Report a vulnerability
If GitHub Advisories are unavailable for your account, contact the repository owner through GitHub profile channels and include:
- clear reproduction steps,
- affected endpoints/files,
- impact assessment,
- possible mitigation (if known).
- Acknowledge report receipt.
- Reproduce and validate the issue.
- Prepare and test a fix.
- Publish patch and advisory notes.
Thanks for helping keep the project and users safe.