For repository security reporting, see the root-level SECURITY.md.

Summary

  • report vulnerabilities privately rather than through public issues
  • the project supports the latest release on main
  • sensitive areas include HTTP transport behavior, dependency security, malformed input handling, and accidental disclosure through logs

Repository Policy