Security fixes are applied to the latest commit on master; no older release branches are maintained
at this stage.
Do not publish a vulnerability that could enable unauthorized writes, credential exposure, signature forgery, replay bypass, unsafe target selection, or code execution through a public issue. Use the repository's private security-advisory reporting channel if it is enabled. Otherwise, contact the maintainer through the GitHub profile listed in the repository metadata and include reproducible steps, impact, and a minimal proof of concept.
Reports receive an acknowledgement as soon as practical. Please allow time for investigation and a fix before public disclosure.