Security fixes are applied to the latest released minor version.
Do not open a public issue for a vulnerability that could put users or data at risk. Use GitHub's private vulnerability reporting for this repository. If that is unavailable, email sam25@mails.tsinghua.edu.cn with reproduction steps and impact.
The project has no runtime dependencies and does not make network requests, but packaging, CLI, and Unicode-processing issues are still in scope.