If you have encountered a potential security vulnerability in this project, please report it to us as a new issue. We will work with you to verify the vulnerability and patch it.
If we verify a reported security vulnerability, our policy is:
-
We will patch the current release branch, as well as the immediate prior minor release branch.
-
After patching the release branches, we will immediately issue new security fix releases for each patched release branch.
-
A security advisory will be released on the project website detailing the vulnerability, as well as recommendations for end-users to protect themselves.