The supported version is the latest tagged release. PRISM does not require credentials for its core package. Some archived experiments use external model APIs; credentials must be provided at runtime and must never be committed.
Please report a suspected vulnerability privately to the repository owner through the contact method listed in the GitHub profile. Include affected versions, a minimal reproduction, impact, and any suggested mitigation. Do not open a public issue until a fix or disclosure plan is agreed.