| Version | Supported |
|---|---|
| 0.4.x | Yes |
| 0.3.x | Security fixes only |
| < 0.3 | No |
Preferred: Use GitHub Security Advisories to report vulnerabilities privately.
Alternative: Email protoscience@anulum.li with:
- Description of the vulnerability
- Steps to reproduce
- Impact assessment
Response SLA:
- 48 hours: acknowledgement
- 7 days: initial assessment and severity classification
- Fix timeline communicated after assessment
Do not disclose publicly before a fix is released. We will credit reporters in the changelog unless anonymity is requested.