This repository is under active development. Security fixes are evaluated
against the main branch and the latest published release, when a release is
available. Older commits and unreleased feature branches may not receive a
backport.
Please report suspected vulnerabilities privately through GitHub's Report a vulnerability flow on this repository's Security tab. Include only the minimum information needed to reproduce the issue and avoid real user data, private keys, or production credentials.
If private vulnerability reporting is not enabled, contact a repository maintainer through their GitHub profile and request a private channel. Do not include exploit details in a public issue, pull request, or discussion.
Please include:
- the affected commit, release, or route;
- concise reproduction steps and expected versus observed behaviour;
- the security impact and any prerequisites; and
- a minimal proof of concept that uses only local or test data.
We will acknowledge a report when a maintainer is available, work with the reporter to reproduce it, and share remediation or disclosure timing when the scope and impact are understood. This is a contributor-run project, so exact response and fix timelines cannot be guaranteed.
Good-faith research is welcome when it avoids privacy violations, service degradation, or disruption of other users. Do not access data that is not yours, submit transactions with real value, use stolen credentials, probe production systems, perform denial-of-service testing, or contact users.
Please stop testing and report privately as soon as you confirm a potential issue. We will not pursue legal action for research that follows this policy, stays within the repository's own code and test environments, and avoids accessing or modifying other people's data.