Security policy
Learn how to responsibly report a security issue.
We have a 3 month release cycle, and the last two versions are supported.
To report security vulnerabilities, please send an email to one of the following addresses:
Note: These email addresses are exclusively for vulnerability reporting.
For all other inquiries/communication, please refer to the Reach Out to Us section in our README.
The following keys may be used to communicate sensitive information to developers, and to validate signatures on releases:
You can import a key by running the following command with that individual’s fingerprint:
gpg --keyserver hkps://keys.openpgp.org --recv-keys "<fingerprint>".
Ensure that you put quotes around fingerprints containing spaces.