The latest release receives security fixes. Report issues against the current
main branch.
Report vulnerabilities privately through GitHub Security Advisories or email info@simiancraft.com. Do not open a public issue for a vulnerability.
We aim to acknowledge reports within three business days and provide a patch or mitigation plan within 14 days of confirmation.
In scope: supply-chain compromise, unintended files or credentials in release artifacts, and unsafe processing of untrusted interval or recurrence data as those features ship. Ordinary rendering and geometry errors belong in bug reports. Report vulnerabilities in peer dependencies to their upstream maintainers.