Security fixes are applied to the current main branch and the latest published release.
Please do not open public GitHub issues for security vulnerabilities.
Instead:
- Use GitHub's private vulnerability reporting flow for this repository if it is enabled.
- If private reporting is unavailable, contact the maintainers privately before disclosing details publicly.
Include:
- a description of the issue
- affected versions
- reproduction steps or a proof of concept
- impact assessment if known
We will review reports privately, confirm impact, and coordinate a fix before public disclosure when appropriate.