Security fixes are provided for the latest stable major release. Critical fixes may also be backported to the previous major release when practical.
Do not open a public issue for a suspected vulnerability. Use GitHub private vulnerability reporting for this repository, or email harbzali@gmail.com with:
- the affected version;
- reproduction steps or a proof of concept;
- the likely impact;
- any suggested mitigation.
You can expect an acknowledgement within five business days. Please allow time for a coordinated fix before publishing details.
Reports involving authorization bypass, cross-tenant disclosure, unsafe restore/revert behavior, redaction failures, export exposure, or integrity verification are especially welcome.