We support security updates for the following versions of collections:
| Version | Supported |
|---|---|
| Latest | ✅ |
| < 1.0 | ❌ |
We take the security of collections seriously. If you discover a security vulnerability, please report it responsibly by following these steps:
- Do not report security vulnerabilities through public GitHub issues or discussions.
- Please use the GitHub Private Vulnerability Reporting feature on this repository.
- If private vulnerability reporting is unavailable, email the maintainer directly.
To help us triage and resolve the issue quickly, please include:
- A detailed description of the vulnerability.
- Steps to reproduce the issue or a minimal Go code reproducer.
- Impact assessment (e.g. denial of service, memory corruption, unexpected data exposure).
- Any suggested fixes or mitigations.
- We will acknowledge receipt of your vulnerability report within 48 hours.
- We will provide a status update and estimated timeline for a fix within 7 days.
- Once a fix is verified, a patch release and security advisory will be published.