This is the default security policy for repositories that do not include their
own SECURITY.md. If a repository has its own policy, follow that one.
Security updates are provided for:
- The latest release
- The default branch
Older releases may receive fixes at the maintainer's discretion.
Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.
Use one of these channels instead:
- GitHub Private Vulnerability Reporting: open Security → Report a vulnerability on the repository, when the feature is enabled.
- Email lzm0x219@gmail.com with a subject that identifies the repository and that the message is a security report.
Include as much of the following as you can:
- A description of the vulnerability
- Steps to reproduce, or a proof of concept
- Affected versions, tags, or commits
- The impact, if you have assessed it
- Any suggested remediation
You should receive an acknowledgement within a few business days. After that, we will try to reproduce the issue and tell you whether it was accepted or declined.
If the report is accepted, we will work on a fix and coordinate public disclosure with you. If it is declined, we will explain why.
Please do not disclose the issue publicly until a fix has been released, or until we have agreed on a disclosure date.
This policy covers vulnerabilities in the repository's own code.
Report issues in third-party dependencies to the upstream project, unless the vulnerability is in how this project uses them.