Do not open a public issue for security problems.
Report vulnerabilities privately, either through GitHub private vulnerability reporting or by email to info@gopherium.com.
You will receive an acknowledgement within 7 days. Please include a description of the issue, a proof of concept if you have one, and the version or commit you tested against. Coordinated disclosure is appreciated: give us a chance to ship a fix before publishing details.
Only the latest release of each module receives security fixes. While a module is at v0.x there are no backport guarantees.
In scope: flaws in the code the modules in this repository ship. Out of scope: how a consuming application wires those modules into its stack.