Security fixes are applied to the latest release and the main branch.
Do not open a public issue for a suspected vulnerability.
Use GitHub's private vulnerability reporting feature from the repository's Security tab. If it is unavailable, contact the repository owner privately using the contact method on their GitHub profile.
Include a clear description, affected version or commit, reproduction steps, impact, and any suggested mitigation. Remove personal or sensitive data from reports.
You can expect an acknowledgement within seven days. After validation, maintainers will coordinate a fix and disclosure timeline with you. Please allow reasonable time for a patch before publishing details.