Security fixes are provided for the latest published version when maintainers can reproduce and address the issue. Older versions are unsupported.
| Version | Supported |
|---|---|
| Latest published release/tag | Yes |
| Older versions | No |
| Unreleased development code | Best effort |
Do not open a public issue containing exploit details, credentials, cookies, signed media URLs, or other sensitive information.
Use Security → Advisories → Report a vulnerability in this repository. GitHub private vulnerability reporting keeps the initial report out of public Issues.
Include, privately:
- Affected version and TV/Tizen/TizenBrew or Android TV/WebView configuration
- Impact and prerequisites
- Reproduction steps or a minimal proof of concept
- Any suggested mitigation
- Whether the issue has been disclosed elsewhere
Please allow maintainers a reasonable opportunity to investigate and coordinate a fix before public disclosure. The project will acknowledge receipt, assess scope, prepare a fix when feasible, and credit reporters who want credit.