Security fixes are applied to the active main branch.
Please do not open public issues for security vulnerabilities.
Report privately with:
- clear description of the issue
- reproduction steps and impacted components
- potential impact assessment
Suggested channels:
- repository security advisories (preferred)
- direct maintainer contact
- initial acknowledgement: within 72 hours
- triage and severity classification: as soon as reproducible
- remediation timeline: based on severity and exploitability
- JWT + refresh token rotation
- Redis-backed token denylist and rate limiting
- RBAC and permission model
- CSRF/CORS controls
- structured audit logs and trace correlation
- security headers at app and edge layers