If you discover a security vulnerability, please report it responsibly:
- Do NOT open a public issue
- Email security concerns to the repository maintainers
- Allow reasonable time for assessment and remediation before disclosure
| Version | Supported |
|---|---|
| main | ✓ |
- Regular dependency updates via automated tooling
- CI-based security scanning where applicable
- Docker builds use pinned base images
We follow responsible disclosure practices and aim to:
- Acknowledge reports within 48 hours
- Provide initial assessment within 7 days
- Release fixes as appropriate