Please report security issues privately through GitHub's private vulnerability reporting if it is enabled for the repository.
If private vulnerability reporting is not available, open a minimal issue that does not include exploit details and request a private contact path.
Security fixes target the latest commit on the default branch until versioned releases are published.
Security-sensitive areas include malformed input handling, denial-of-service risks from extremely large inputs, and unsafe memory usage in tokenizer hot paths.