Security fixes are provided for the latest released version.
Please do not open public issues for security vulnerabilities.
Report vulnerabilities privately by using GitHub's private vulnerability reporting for this repository.
When reporting, include:
- A clear description of the issue and impact
- Reproduction steps or a proof of concept
- Any affected versions, commit hashes, or environments
- Suggested mitigations (if known)
You can expect an initial response within 7 days.
After confirmation, fixes will be prepared and released. We will coordinate disclosure timing with reporters when possible.