Security fixes land on the latest release and the main branch. Older releases do
not receive separate security patches.
Use GitHub's private vulnerability report. Do not open a public issue for an unpatched vulnerability.
Include the affected path, impact, reproduction steps, and any suggested mitigation. Do not include real credentials, personal data, or production payloads.
You should receive an acknowledgment within seven days. The report will remain private until a fix is available or disclosure terms are agreed.