Please do not report security vulnerabilities through public GitHub issues.
Report suspected vulnerabilities to GovTech Vulnerability Disclosure Programme pag. Include:
- A description of the issue and its potential impact
- Steps to reproduce, or a proof of concept
- Affected version(s) or commit
- Acknowledgement: we aim to acknowledge your report within 3 working days.
- Updates: we will keep you informed as we investigate and work on a fix.
- Disclosure: we follow coordinated disclosure and will agree timing with you before any public disclosure.
Note that only the latest release is supported.
Where available, this project follows GovTech's coordinated vulnerability disclosure policy.