Each Capell 1.x minor receives security fixes for 24 months from its release date. The latest 1.x minor is always supported. Upgrade all installed Capell foundation packages together to the same supported release before requesting a fix.
If you discover a security vulnerability in Capell, email [email protected].
Include the affected package/version, a short reproduction, impact, and any relevant logs or screenshots. Do not open a public GitHub issue for an undisclosed vulnerability.
We aim to acknowledge reports within 2 business days, confirm impact and affected versions after triage, and coordinate a fix or mitigation before public disclosure.