Security Policy
Supported versions
Only the latest release available on the Releases page is supported with security updates.
Reporting a vulnerability
Please report security issues privately:
- Go to the Security tab of this repository.
- Click Report a vulnerability (private vulnerability reporting).
- Describe the issue, impact, and steps to reproduce.
Do not open a public issue for anything you believe is exploitable.
For issues that cannot use GitHub Security Advisories, email security@neohiro.io (PGP key on request). All reports get an acknowledgement within 72 hours.
You can expect an initial response within 7 days. Please allow a reasonable time for a fix before any public disclosure.
Hardening notes
This is a static documentation site. Reports about content injection or a build step executing untrusted input are most relevant.
Maintained by neohiro.