Security
This is a personal project maintained by a single developer. There is no dedicated security team or bug bounty program, but reports are welcome and will be looked at.
Reporting a vulnerability
Section titled “Reporting a vulnerability”Please do not open a public GitHub issue for security vulnerabilities.
Report privately instead, via either:
Please include a description of the issue, steps to reproduce, and the potential impact where known.
Response
Section titled “Response”There’s no formal SLA — expect an acknowledgement within a few days. Fixes are prioritized by severity and released when ready.
Supported versions
Section titled “Supported versions”Only the latest released version receives security fixes.