Until the first stable release, security fixes are applied to the latest code
on main.
Use GitHub's private vulnerability-reporting feature when it is available. Do not publish exploit details, private timeline data, database files, credentials, or machine-specific paths in a public issue.
Include a concise impact description, affected version or commit, reproduction conditions, and any proposed mitigation. Maintainers will acknowledge a valid report as soon as practical and coordinate disclosure after a fix is ready.