Security fixes are currently prioritized for the latest main branch and the most recent tagged beta release.
Please do not open public issues for security vulnerabilities.
Report vulnerabilities by emailing: [email protected]
Include:
- affected component and version/commit
- reproduction steps or proof of concept
- impact assessment
- suggested remediation (if known)
- Initial acknowledgment: within 3 business days
- Triage status update: within 7 business days
- Remediation plan: as soon as impact is confirmed
We will coordinate disclosure timing with reporters and credit responsible disclosure unless anonymity is requested.