- Security SLA: We do not provide a security SLA for community users. Users are encouraged to review the code and report any vulnerabilities they find.
- Release schedule: Releases prioritize new features and include fixes for known security vulnerabilities at release time. However, there is no guarantee that all vulnerabilities will be fixed in every release.
- Version support: We may provide the project's latest version, but we do not guarantee support for older versions. Users are encouraged to upgrade to the newest version to benefit from security fixes.
If you discover a security vulnerability within this project, please report it through GitHub Security Advisories so the issue can be addressed privately before public disclosure.
If you cannot use Security Advisories, please avoid posting exploit or impact details in a public issue or pull request. Instead, open an issue that only states a security report is pending and ask a maintainer to reach out, or contact the maintainer directly using the address in CODE_OF_CONDUCT.md.
Your contributions to improving the security of this project are greatly appreciated.