| Version | Supported |
|---|---|
| 0.0.x | Yes |
Report security vulnerabilities by emailing sebastian.rousseau@gmail.com.
Do not open a public issue for security reports.
Include:
- A description of the vulnerability.
- Steps to reproduce.
- Affected versions.
- Any suggested fix (optional).
Expect an initial response within 48 hours. A fix or mitigation plan will follow within 7 days of confirmation.
All commits on the main branch are signed, and releases are signed tags. The release-signing key is published in KEYS.asc:
4B7F16C909C7A8EE9BED338A4F047EDF5F90F638
Signing key Sebastien Rousseau <sebastian.rousseau@gmail.com>, ed25519, signing-only, expires 2028-08-16. Verify the fingerprint out of band before trusting it.