| Version | Status |
|---|---|
| 1.6.x | Supported (current release line) |
| 1.5.x | Best-effort fixes for one minor cycle |
| < 1.5 | No longer supported |
Report suspected vulnerabilities through GitHub private security advisories. Do not open public issues for security concerns.
Include a description, reproduction steps, affected version, and operational impact. Maintainer response target: 7 days.
In scope: defects in the application code, dependencies, container images, CI/CD configuration, and release artifacts published from this repository.
Out of scope: third-party services or self-hosted infrastructure outside this repository, social engineering of contributors, denial-of-service against community resources.