| Version | Supported |
|---|---|
| 0.1.x | Yes |
| Earlier versions | No |
Do not open a public issue for a suspected vulnerability. Use GitHub private vulnerability reporting and include affected versions, reproduction steps, impact, and any suggested mitigation. Do not include live credentials; revoke and rotate any credential that may already be exposed.
The maintainer will acknowledge a complete report when practical, investigate it privately, and coordinate disclosure after a fix or mitigation is available. This policy does not promise a fixed response deadline for an early volunteer-maintained release.