Home
Project

Security

Private vulnerability reporting and supported release policy.

Do not open a public issue for a security problem. Report it through GitHub Security Advisories. The latest minor release receives security fixes; older lines are not patched.

The repository treats pull requests from forks as untrusted. Public validation receives no secrets or write-capable token, while releases and Pages deployment run only from trusted main state.