Report a vulnerability
Do not open a public issue for a suspected vulnerability.
Use the repository's private GitHub security advisory form. Include:
- affected exact version or commit;
- deployment role and topology;
- minimal reproduction steps;
- impact and trust boundary;
- sanitized logs or requests;
- any temporary mitigation.
Do not include customer data, access tokens, passwords, database dumps, certificate private keys, CA keys, signing keys, backup credentials, or raw telemetry.
The project does not publish a fixed response SLA or supported-version matrix in the implementation. Operators should track exact immutable releases and apply security updates after qualification.