Do not open a public GitHub issue for security vulnerabilities.
If you discover a security issue, please report it privately so we can address it before it is disclosed publicly.
DM maintainers directly:
- Ori Simantov — via Linkedin - https://www.linkedin.com/in/ori-simantov-5545a9119
Please do not use GitHub Issues or Discussions for security reports.
Include in your report:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fix (optional but appreciated)
- Acknowledgement within 48 hours
- A fix or mitigation plan within 14 days for critical issues
- Credit in the release notes if you would like it
Only the latest release on main receives security fixes.