Security policy

Learn how to responsibly report a security issue.

We have a 3 month release cycle, and the last two versions are supported.

To report security vulnerabilities, please send an email to one of the following addresses:

Note: These email addresses are exclusively for vulnerability reporting.

For all other inquiries/communication, please refer to the Reach Out to Us section in our README.

The following keys may be used to communicate sensitive information to developers, and to validate signatures on releases:

You can import a key by running the following command with that individual’s fingerprint: gpg --keyserver hkps://keys.openpgp.org --recv-keys "<fingerprint>". Ensure that you put quotes around fingerprints containing spaces.