Only the latest release receives security fixes. The library has no runtime dependencies; its attack surface is parsing untrusted unit-file input (fuzzed continuously in CI).
| Version | Supported |
|---|---|
| latest release | ✅ |
| anything older | ❌ |
Please report vulnerabilities privately via GitHub's security advisories:
Do not open a public issue for security reports. You should receive a response within a week. Once a fix is released, the advisory is published and credited to the reporter unless they prefer otherwise.