Security fixes are applied to the latest version of the main branch and the most recent release.
Please do not open a public issue for a suspected security vulnerability.
Instead, contact the maintainer privately through the email address listed on the maintainer's GitHub profile. Include:
- affected component;
- reproduction steps;
- expected impact;
- proof of concept, if available;
- suggested mitigation, if known.
Please allow reasonable time for investigation before public disclosure.
Relevant reports include, but are not limited to:
- unauthorised data access;
- remote command execution;
- protocol parsing vulnerabilities;
- unsafe deserialisation;
- WAL or snapshot corruption resulting in integrity loss;
- denial-of-service issues;
- authentication or namespace-isolation bypasses.