Security fixes are applied to the latest published minor line. Pre-1.0 releases may contain breaking fixes when safety requires them; consumers should stay current and pin versions through a lockfile.
Please use GitHub's Report a vulnerability option in the repository Security tab. This sends the report privately to the maintainer.
Do not publish trainer-control exploits, identifying Bluetooth captures, tokens, or personal workout data in a public issue. If private vulnerability reporting is temporarily unavailable, open an issue containing no sensitive details and ask the maintainer for a private contact channel.
Include the affected package version, browser and operating system, trainer model and firmware when relevant, reproduction steps, and the safety impact. Never reproduce a resistance-control problem while riding the trainer.
The maintainer aims to acknowledge reports within three business days and provide an initial severity assessment within seven. Resolution time depends on hardware access and coordinated disclosure risk. Critical trainer-control reports may block releases or require an immediate advisory before a fix is available.