Before the first tagged release, security fixes are applied to the latest commit on the default branch. After release, the latest supported major version receives security fixes.
Do not open a public GitHub issue for a suspected vulnerability.
Email support@hcaptcha.com and copy security@hcaptcha.com. Include the
affected version or commit, impact, reproduction steps, and any proposed
mitigation. Do not include live hCaptcha secrets, response tokens, customer
data, or other credentials. Use only accounts and systems you are authorized to
test, avoid privacy violations and service disruption, and allow time for
coordinated remediation before disclosure.
For ordinary integration questions and non-security bugs, use the public issue tracker after the repository is released.