Skip to content

Security policy

English · 简体中文

Supported versions

The latest released minor version receives security updates. Pre-releases are for verification only and carry no long-term maintenance commitment.

Reporting a vulnerability

Please report privately via Security → Report a vulnerability on the GitHub repository. Do not open a public issue.

Include the affected versions, a minimal reproduction, the scope of impact and, if you have one, a suggested fix. A maintainer will confirm as soon as possible and coordinate disclosure timing until a fix is available. Please do not access systems or data that are not yours while testing.

This project will never ask a reporter for passwords, tokens, private keys or other sensitive credentials.

Released under the MIT License.