Only the latest commit on main receives security fixes.
Report vulnerabilities privately through GitHub's Report a vulnerability flow. Do not place exploit details, bridge keys, capabilities, private paths, or secret contents in a public issue.
Capability leakage, path or symlink escape, unauthorized reads, sandbox escape, and secret exposure are in scope.