Security fixes target the current default branch. Older releases may not receive backports.
Do not open a public issue for a suspected vulnerability. Use GitHub private vulnerability reporting and include the affected revision, impact, reproduction steps, and any suggested mitigation.
Avoid including live credentials, proprietary market data, or personal data in the report. The maintainer will acknowledge the report, assess severity, and coordinate remediation and disclosure through the private advisory.