| Version | Supported |
|---|---|
0.1.x |
Yes |
<0.1.0 |
No |
Please report security issues privately through GitHub Security Advisories:
- Open the repository
Securitytab. - Create a private vulnerability report with reproduction steps and impact.
- Include affected version(s), platform, and proof-of-concept details.
If Security Advisories are unavailable, open a private maintainer contact issue and avoid publishing exploit details.
- We acknowledge valid reports within 3 business days.
- We triage severity and impacted versions.
- We ship a fix and publish an advisory once users can patch safely.
Current Linux desktop dependencies pulled by wry/tao include GTK3-related crates with RustSec warnings (unmaintained/unsound notices). These are tracked in scripts/ci/cargo-audit-ignore.json and are temporarily allowlisted until upstream migration removes the affected stack.