We take the security of the Siren SDK seriously. If you discover a security vulnerability, please report it privately — do not open a public issue or pull request.
Report vulnerabilities through GitHub's private reporting:
- Go to the Security Advisories page.
- Click Report a vulnerability.
- Provide as much detail as you can: affected version, a description of the issue, and steps to reproduce.
We will acknowledge your report, investigate, and keep you informed of the resolution. Once a fix is available and released, we will publish an advisory and credit you if you wish.
Security fixes are applied to the latest released minor version. Please make sure you are on a current release before reporting.