Security fixes are made for the latest release published from this repository
and for the current main branch while the next release is under active
development. Older releases may not receive backported fixes, so users should
update to the latest available version.
Please report suspected vulnerabilities privately through GitHub's Report a vulnerability form. Do not open a public issue or discussion for an unpatched vulnerability.
Include, when possible:
- the affected Home version and operating system;
- steps or a minimal example that reproduce the issue;
- the security impact and any known prerequisites; and
- a suggested mitigation or fix, if one is available.
Do not include passwords, private keys, recovery phrases, API keys, or other live secrets in the report. Use test data that can be safely discarded.
The maintainers will acknowledge the report as soon as practical, investigate it, and coordinate remediation and disclosure with the reporter. Please keep the details private until a fix or agreed disclosure plan is available.