Developers

Security policy

Supported versions and the private channel for reporting a vulnerability.

Security fixes target the latest 0.1.x release and the current main branch. Older releases, other branches and forks are not supported; the deleted historical v1.0.0 tag must not be recreated.

Reporting

Use the product repository's private vulnerability reporting form.

If private reporting is unavailable, open a minimal public issue asking for a private contact channel. Do not include exploit code, credentials, private data, or other sensitive details in that issue.

Include the affected commit or image tag, clear reproduction steps, the expected impact, and a sanitized proof of concept when possible. You should receive an acknowledgement within seven days and an initial assessment within fourteen days.

General scientific-data corrections and display bugs are not security vulnerabilities and should use the normal issue tracker.

The authoritative text remains SECURITY.md.