Security updates are applied to the latest master release line.
Please do not open public GitHub issues for security reports.
Send a report to security@stateset.com with:
- A clear description of the issue and impact.
- Reproduction steps or proof-of-concept.
- Affected version/commit and environment details.
- Any suggested remediation.
- Initial acknowledgment: within 2 business days.
- Triage and severity assignment: as soon as reproducibility is confirmed.
- Fix timeline: based on severity and exploitability.
- Coordinated disclosure: after patch availability.