Security fixes only land in the latest release — there's no backporting to older builds.
| Version | Supported |
|---|---|
| 0.2.x | ✅ Yes |
| < 0.2.0 | ❌ No |
Before reporting, make sure your finding reproduces on the latest release. If it only exists in an older build, the fix is updating — though if something old is nasty enough, we may still put out an advisory so people know to move.
We take the security of this project seriously. If you believe you have found a security vulnerability, do not report it through a public GitHub issue or in public Discord channels.
Please report vulnerabilities using one of the following methods:
- GitHub Private Vulnerability Reporting: Use the Security Advisories tab in this repository.
- Discord ticket: Join our Discord and open a private ticket.
Please include as much of the following information as possible to help us understand and reproduce the issue:
- Type of vulnerability
- The version you tested (reproduce on the latest release first)
- Step-by-step instructions to reproduce the issue
- Proof-of-concept (if available)
- Your views on potential impact
We kindly ask that you:
- Give us a reasonable amount of time to address the issue before public disclosure.
- Avoid accessing or modifying data that does not belong to you.
- Act in good faith and avoid actions that could harm the project or its users.