Only the latest released version receives security fixes. Please upgrade before reporting, or mention your version if you can't.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, report a vulnerability using GitHub's private vulnerability reporting.
Please include:
- A description of the vulnerability and its impact
- Steps to reproduce it
- The affected version(s)
- Any special configuration required to reproduce it
- Full paths of any source files related to the issue, if known
- Any relevant logs, screenshots, or proof-of-concept code
This covers vulnerabilities in this project's own code. For a dependency, please report to that project directly.
- We will acknowledge your report as soon as possible.
- We will investigate and work on a fix.
Security research conducted in good faith, following this policy, and without harming users, data, or service availability, is authorized. We will not pursue legal action for reports that comply with this policy.