Security fixes target the latest release and the current default branch. Older releases may not receive backports unless the project documents otherwise.
Do not open a public issue for a suspected vulnerability.
- Use GitHub's private vulnerability reporting page: https://github.com/{{GITHUB_OWNER}}/{{PROJECT_SLUG}}/security/advisories/new
- If private reporting is unavailable, contact {{SECURITY_CONTACT}} privately.
- Include the affected version, impact, reproduction steps, and any proposed mitigation.
- Do not include credentials, private user data, or active exploit material beyond what is needed to reproduce the issue safely.
Maintainers will review the report, coordinate remediation, and disclose the issue after a fix or mitigation is available.
Reports about vulnerabilities in this project's code, release artifacts, or documented deployment paths are in scope. General support questions and feature requests belong in the normal issue tracker.