Revia follows semantic versioning.
Security releases will be published as patches to the latest release of the affected major version. While Revia is in v0.x, supported versions will receive security updates as necessary.
Please do not report security vulnerabilities through public GitHub issues.
Instead, use GitHub's private security advisory reporting for this repository. Include a clear description, reproduction steps where possible, affected versions, and any suggested mitigation.
Reports will be reviewed as quickly as possible. Once a fix is ready, we will publish a security release and coordinate disclosure where appropriate.