Please report suspected vulnerabilities privately via GitHub private vulnerability reporting ("Report a vulnerability" on the repository's Security tab).
Do not open a public issue for security problems — public issues are visible immediately, before a fix exists.
This is a solo-maintained project: reports are handled on a best-effort basis. You should normally hear back within a week.
Only the latest release (and the container image tags derived from it,
latest / the newest CalVer tag) receives security fixes. There are no
backports to older versions — update by pulling the newest release.