Please report suspected vulnerabilities privately through the repository's GitHub security advisories page rather than opening a public issue. Include the affected version, a minimal reproduction, and any relevant impact or mitigation details.
We will acknowledge reports as soon as practical and coordinate a fix and disclosure timeline with the reporter. Security fixes are provided in the latest supported release; users should upgrade promptly when a security advisory is published.