Nisshi is pre-1.0 and moves quickly. Security fixes land on main and ship
in the next release; we don't maintain older release branches.
Please don't open a public issue for a security vulnerability.
Preferred: use GitHub's private vulnerability reporting for this repository (Security tab → Report a vulnerability). This creates a private advisory visible only to maintainers until a fix is ready.
Fallback: email peter.james.morgan@gmail.com with details. Include:
- The version or commit you tested against
- Steps to reproduce, or a proof of concept
- The impact you believe the issue has
We'll acknowledge your report, work with you to understand the impact, and coordinate on a disclosure timeline once a fix or mitigation is ready.