Security fixes are made on the latest released version and main. Older
versions are not maintained separately.
Use GitHub's Report a vulnerability button on the repository's Security page. This creates a private advisory visible only to the reporter and maintainer. Do not disclose a suspected vulnerability in a public issue, discussion, or pull request.
Include affected versions, impact, reproduction steps, and any suggested fix. You should receive an acknowledgement within seven days. Release timing depends on severity and the complexity of a safe fix.
Never include real credentials, private repository data, or unrelated personal information in a report or reproduction.