Security fixes are applied on the main branch. Tagged releases, when published,
receive backports at the maintainers' discretion.
Please report security issues privately to michael@snowmead.com.
Include:
- A description of the issue and its impact
- Steps to reproduce, or a minimal proof of concept if available
- Affected crates, versions, or commit SHAs if known
Do not open public GitHub issues for undisclosed security vulnerabilities.
We aim to acknowledge reports within 72 hours and will coordinate disclosure timelines with reporters when fixes are in progress.