Security policy
English · 简体中文
Supported versions
The latest released minor version receives security updates. Pre-releases are for verification only and carry no long-term maintenance commitment.
Reporting a vulnerability
Please report privately via Security → Report a vulnerability on the GitHub repository. Do not open a public issue.
Include the affected versions, a minimal reproduction, the scope of impact and, if you have one, a suggested fix. A maintainer will confirm as soon as possible and coordinate disclosure timing until a fix is available. Please do not access systems or data that are not yours while testing.
This project will never ask a reporter for passwords, tokens, private keys or other sensitive credentials.