Security fixes are applied to the latest version.
If you find a potential security issue, please report it using the private vulnerability reporting feature of GitHub to automatically inform all relevant team members. Otherwise, please get in touch with stefan6419846 through e-mail (current maintainer, address in GitHub profile).
We will try to find a fix in a timely manner and then issue a security advisory together with the update via GitHub, as well as requesting a CVE (example).
If you do not get a reaction within 30 days, please open a public issue on GitHub.
Additional aspects to consider:
- Please have a look at our corresponding user documentation, which includes some information about possibly invalid reports.
- Respect our AI policy.
- Reported issues we are unable to reproduce due to an invalid or missing proof-of-concept might be closed directly.
- If you propose to add limits, please tell us which you would propose and why.
- If you provide a fix, please make sure it is self-explanatory and can actually be executed.
- Issues related to vulnerable OS or third-party libraries, as well as improper library usage from our users, are usually not considered security issues on our side.