| Version | Supported |
|---|---|
| 1.x.x | Yes |
| < 1.0 | No |
If you discover a security vulnerability, please report it by:
- Opening a private security advisory in this repository
- Providing a detailed description of the vulnerability
- Including steps to reproduce the issue
- Suggesting a fix if possible
Please do not disclose security vulnerabilities publicly until they have been addressed.
- Initial response: within 48 hours
- Status update: within 7 days
- Fix timeline: depends on severity
This project follows these security practices:
- Dependencies are regularly updated via Dependabot
- All PRs require review before merging
- Sensitive data is never committed to the repository
- Environment variables are used for secrets