The latest release on main is considered supported for security fixes.
Do not open a public issue for a live security problem.
Report security issues privately to the repository owner through GitHub security advisories or direct contact if available.
Include:
- A clear description of the issue
- Affected version or commit
- Steps to reproduce
- Any logs, traces, or proof of concept
Never commit real webhook URLs, tokens, or .env files to the repository.