English | 简体中文
Security fixes are prioritized for the latest stable release and the main branch. Older releases are not maintained.
| Version | Supported |
|---|---|
| Latest stable release | Yes |
main |
Best effort |
| Older releases | No |
Please do not report security vulnerabilities in a public issue, pull request, or discussion.
Use GitHub Private Vulnerability Reporting so the report stays private while it is investigated.
Please include:
- the affected version or commit;
- the security impact;
- reproduction steps or a proof of concept; and
- relevant operating-system and installation details.
Remove real credentials and personal data from the report. If a credential may have been exposed, revoke or rotate it immediately.
If private reporting is unavailable, contact the maintainer through @wzz6423 and do not disclose sensitive details publicly.
We aim to acknowledge a report within 7 calendar days and provide an initial assessment or status update within 14 calendar days. We will coordinate any public disclosure with the reporter after a fix or mitigation is available.