The project maintainers take the security of our software seriously. We appreciate your efforts to responsibly disclose your findings, and we will make every effort to acknowledge your contributions.
We are committed to providing security updates for the versions listed below. If you are using an unsupported version, please upgrade to a supported version.
| Version | Supported |
|---|---|
1.x.x |
✅ |
< 1.0 |
❌ |
If you believe you have found a security vulnerability in this project, please do not create a public GitHub issue. Instead, we ask you to report it privately to ensure the security of our users.
Please follow these steps:
-
📧 Email Us: Send a detailed report to our private security alias: [YOUR SECURITY CONTACT EMAIL] (e.g.,
security@example.com). -
Provide Detailed Information: To help us resolve the issue quickly, please include the following in your report:
- A clear and descriptive title.
- The component and version(s) affected.
- A detailed description of the vulnerability.
- Steps to reproduce: Provide a clear, step-by-step guide to reproduce the vulnerability. Include any necessary code snippets, screenshots, or proof-of-concept exploits.
- The potential impact of the vulnerability.
-
Confidentiality: Please treat the vulnerability report as confidential. Do not disclose the issue publicly until we have had a chance to address it and release a patch.
When you report a vulnerability to us, we promise the following:
- Acknowledgement: We will acknowledge receipt of your report within 48 hours.
- Communication: We will provide you with a status update at least once every 7 days.
- Resolution: We will work diligently to investigate and fix the vulnerability. Once resolved, we will notify you.
- Recognition: We believe in recognizing the work of security researchers. If you agree, we will be happy to credit you in our release notes once the vulnerability has been patched.
Security is a collaborative effort, and we consider you a vital partner in protecting our community. Thank you for your contribution to a safer open-source ecosystem.