We support the latest release on the main branch (e.g., v4.5.x). Older releases may not receive security patches.
Please do not open public GitHub issues for security problems.
- Use GitHub’s “Report a vulnerability” (Security Advisory) feature if available for this repository
- Alternatively, contact the maintainer privately via their GitHub profile (@swadhinbiswas)
Provide as much detail as possible:
- Affected version(s) and environment (OS, shell)
- Steps to reproduce and a minimal proof of concept
- Impact assessment (what could an attacker do?)
We will acknowledge receipt within 3 business days and provide an initial assessment/ETA as soon as possible.
We prefer coordinated disclosure. Once a fix is available, we will publish a new release and acknowledge reporters who wish to be credited.