The latest version on the default branch is the supported version.
Please do not open a public issue for a security problem that could put users at risk.
Preferred path:
- Use GitHub Private Vulnerability Reporting if it is enabled for the repository.
- If private reporting is not available yet, contact the maintainer privately before publishing details.
When reporting, include:
- affected version or commit
- steps to reproduce
- impact
- any proof-of-concept details needed to verify the issue
You can expect:
- an initial acknowledgement after review
- confirmation once the issue is reproduced
- a fix or mitigation plan when the report is valid