| Version | Supported |
|---|---|
| 0.1.x | Yes |
If you discover a security vulnerability, please report it responsibly:
- Do not open a public GitHub issue
- Email security concerns to the maintainers
- Include a description of the vulnerability and steps to reproduce
- Allow reasonable time for a fix before public disclosure
We aim to acknowledge reports within 48 hours and provide a fix or mitigation plan within 7 days.
- All CI actions use hash-pinned versions
- Dependencies are audited via
cargo-denyon every PR - Automated dependency updates via Renovate
- License compliance checked on every build