Security fixes are applied to the latest maintained state of the master branch unless stated otherwise.
Please do not disclose security issues publicly before review.
Preferred process:
- Use GitHub Security Advisories / private reporting if available.
- If private reporting is unavailable, open a limited issue without exploit details and request a private follow-up channel.
- Include impact, reproduction steps, affected area, and any mitigation ideas.
We will review the report, validate impact, and coordinate a fix before public disclosure.
The dependency version baseline and upgrade procedure are documented in docs/DEPENDENCY_SECURITY.md. Pull requests also run automated dependency review through GitHub Actions.