Security fixes are applied to the latest release and the current master
branch. Older versions are not maintained unless explicitly announced.
Use the repository host's private vulnerability-reporting or security-advisory feature. On GitHub, choose Security → Report a vulnerability. Do not include exploit details, secrets, or personal data in a public issue.
Include the affected version or commit, impact, reproduction steps, and any suggested mitigation. Please allow maintainers time to investigate and prepare a fix before public disclosure. No response-time SLA is promised.
For expected trust boundaries and known limitations, see the threat model.