This project supports security updates for the latest released version only. Please upgrade to the most recent release before reporting an issue against an older version.
| Version | Supported |
|---|---|
| Latest release | ✅ |
| Older releases | ❌ |
Please report suspected vulnerabilities privately. Do not open a public issue or pull request for security reports.
Report a vulnerability using one of the following private channels:
- GitHub Security Advisories (preferred): use the repository's Report a vulnerability feature.
- Email: vkluzner@jhu.edu
What to expect after you report an issue:
- We will acknowledge receipt within 3 business days.
- We will provide a status update within 7 business days after acknowledgement.
- If the report is accepted, we will work on a fix and coordinate disclosure with you before publishing details.
- If the report is declined, we will explain why (for example, if the behavior is not considered a security issue or cannot be reproduced).
Please include, where possible, a description of the issue, affected versions, reproduction steps, proof-of-concept details, and any suggested mitigations.