Security fixes are made on the latest code on the main branch. Please update to the latest release before reporting a vulnerability where possible.
Please do not report suspected vulnerabilities in a public issue or pull request. Instead, submit a private GitHub security advisory.
Include a clear description, affected versions or commit, reproduction steps, impact, and a proof of concept when it is safe to share one. We will acknowledge the report, investigate it, and coordinate a fix and disclosure timeline with you.
If private reporting is unavailable for your account, contact a repository maintainer through GitHub and avoid sharing exploit details publicly.