Security fixes target the latest release.
Do not report vulnerabilities or expose proxy credentials in a public issue. Use GitHub's private vulnerability reporting for this repository. Include the affected version, impact, reproduction steps, and a minimal proof of concept without real proxy credentials.
Please allow a reasonable amount of time for investigation before public disclosure.
Application updates are signed and verified independently from operating system code signing. Report suspected update or release-key compromise through GitHub's private vulnerability reporting.